5 ms·
> The Falcon software was not able to wreak similar havoc on Macs because Apple does not give software makers kernel access. In macOS Catalina, which came out i
by lemoncookiechip 2y ago
> The Falcon software was not able to wreak similar havoc on Macs because Apple does not give software makers kernel access. In macOS Catalina, which came out in 2020, Apple deprecated kernel extensions and transitioned to system extensions that run in a user space instead of at a kernel level. The change made Macs more stable and more secure, adding protection against unstable software updates like the one CrowdStrike pushed out. It is not possible for Macs to have a similar failure because of the change that Apple made.
What about Linux though?
Feels like this is just MS redirecting blame and using it as an opportunity to push the narrative that walled garden = good.
- Rinzler89 2y agoThat piece of text you're quoting is mostly incorrect. Falcon didn't break Linux now because they haven't shipped a broken extension for Linux this time, only for Windows, but if you want to, you can definitely cause the Linux kernel to panic quite easily if you start inserting buggy drivers in kernel space like Crowdstrike was doing on Windows.
- janice1999 2y agoSeparate issue from earlier this year, same product: "CrowdStrike's Falcon Sensor also linked to Linux kernel panics and crashes" https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/ https://www.theregister.com/2024/07/21/crowdstrike_linux_cra...
- deleted 2y ago[deleted]
- lemoncookiechip 2y agoQuoting from another thread > mirashii 16 hours ago The primary one linked there is certainly not the same issue, it was a bug in the Linux kernel's ebpf handling. It happened to be triggered by Crowdstrike, but the bug is undeniably a Linux kernel bug which was subsequently patched, as ebpf programs should never be able to panic the kernel. That's not to say that there haven't been other Crowdstrike fails on Linux, especially pre-eBPF module, but that's not one, and that class of failures has been eliminated in the move to the eBPF based module.
- layer8 2y agoCrowdStrike uses eBPF on Linux, which (barring bugs in the kernel’s eBPF implementation) doesn’t cause kernel panics. Microsoft could create a similar safe Windows kernel API if they wanted.
- zokier 2y agoWhat are these then [77384.469522] Modules linked in: falcon_lsm_serviceable(PE) falcon_nf_netcontain(PE) falcon_kal(E) falcon_lsm_pinned_16303(E)
- CRConrad 2y agoIf they panic the kernel, they're presumably software that triggers those bugs in the kernel’s eBPF implementation mentioned in the comment you replied to?
- pwg 2y ago> Falcon didn't break Linux at this incident because they haven't shipped a broken extension for Linux True, but they did break Linux a few months back in much the same way they just broke Windows last Friday: CrowdStrike broke Debian and Rocky Linux months ago, but no one noticed https://www.neowin.net/news/crowdstrike-broke-debian-and-rocky-linux-months-ago-but-no-one-noticed/ https://www.neowin.net/news/crowdstrike-broke-debian-and-roc... But since that break didn't ground a good percentage of global air traffic, it didn't get the same press coverage as this most recent breakage.
- jeroenhd 2y agoThe Linux crashes weren't quite comparable. They accidentally triggered a bug in Red Hat's kernel patches rather than write a bad driver themselves. They can wreak all kinds of havoc with bad eBPF programs, but so far they haven't as far as I know.
- Analemma_ 2y agoI mean from a certain POV the Linux crashes were worse. Everybody understands that buggy kernel-mode drivers can bring down the OS and it's not the OS vendor's fault, but the Linux crashes were exactly what eBPF was supposed to make impossible.