4 ms·
Do you have a source for this? It's the first time I hear of this. From what I've understood (perhaps wrongly), the error came from the CrowdStrike driver (csag
by roblabla 2y ago
Do you have a source for this? It's the first time I hear of this. From what I've understood (perhaps wrongly), the error came from the CrowdStrike driver (csagent.sys) having bugs in their configuration parser that could cause it to BSOD. CrowdStrike pushed a corrupted configuration (the CS-000whatever.sys we're told to delete) that hit that bug. I'm not sure how Microsoft fits in this story.
- mbesto 2y agoJust read more into it. You're correct. I think it would be dumb to solely blame MS, but I don't think you can completely absolve them. this comment right here sums it up: > Sure, but Windows shares some portion of the blame for allowing third-party security vendors to “shit in the kernel”. https://news.ycombinator.com/item?id=41006176 https://news.ycombinator.com/item?id=41006176
- roblabla 2y agoYeah, the fact that Windows requires kernel-level access to be able to do EDR stuff is really unfortunate. MacOS has been very successful with their userspace EndpointSecurity Framework for this purpose. On the other hand, Linux is similarly crippled: eBPF LSM are fairly recent and don't work everywhere (I'm looking at you Ubuntu[0]), and the only real alternative if you want to be able to block processes is a kernel module. Which comes with the same dangers as Windows. [0]: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2054810 https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2054810
- sgift 2y agoWell, Microsoft says that's because of the EU commission: https://news.ycombinator.com/item?id=41029590 https://news.ycombinator.com/item?id=41029590 I have my doubts, but that's at least what they give as the reason for the kernel-level access of EDR tools.