4 ms·
Will they also be summoning the owners of airlines and critical infrastructure that had no fallback or continuity plans in the event of an IT outage?
by BHSPitMonkey 2y ago
Will they also be summoning the owners of airlines and critical infrastructure that had no fallback or continuity plans in the event of an IT outage?
- blackeyeblitzar 2y agoAirlines is bad, but I am more concerned about all the hospitals that shut down entirely or turned away critical surgeries that they suddenly deemed “elective”. Even big prominent hospitals like Mass General! It’s utterly ridiculous but also just a massive risk to public safety and national security that something like this can happen. None of these critical pieces of our society have any real business continuity plan, and it means nothing to them to inconvenience citizens, even if that inconvenience is actually going to result in death.
- paulddraper 2y agoI've always said BC is bullsht and every passing year proves that more correct. I guarantee they all had BC/DR plans. I honestly believe the whole thing in general has net negative ROI just because it never works.
- hsbauauvhabzb 2y agoYou’re assuming it’s boolean though. I guarantee all organisations with decent BC would have performed measurably better than those without it, even if both groups had consistent BSODs.
- Sharlin 2y agoWhat do BC and DR mean in this context?
- gruturo 2y agoBusiness Continuity, Disaster Recovery
- akira2501 2y agoThe entire industry has a monopoly problem with the expected set of related interoperability problems. There's no logical reason we should be running so much infrastructure on Microsoft's monoculture.
- k8sToGo 2y agoI hope you are aware the same thing happened on Linux recently.
- lucianbr 2y agoStill, it did not happen at the same time, did it? Diversity has advantages, even if none of the systems is perfect.
- orwin 2y agoIf "Linux" mean RHEL, and "same thing" mean "redhat eBPF implementation was buggy and caused kernel panic after a few minutes, but you could deactivate it", i'm aware.
- irjustin 2y agoRunning a different OS for each business function is my favorite absurd solution to this problem.
- akira2501 2y ago> absurd solution What's absurd about it? It's absurd that I want the software operating my MRI and providing doctors with necessary information during surgeries to be different from what accountants using Excel and video game players use? What's absurd is congress hoping to solve the fundamental problem by asking the CrowdStrike CEO to come in for a one on one. Even if we took this process at face value and assumed they were earnest it would be laughable. Meanwhile.. the government is the largest healthcare payer in the world. For not particularly great reasons. This _is_ one of the downstream impacts of that reality.
- t0mas88 2y agoFor airlines there are separate risk assessments for flight ops and revenue ops. If the website fails, that costs a lot of money, but nobody is in danger. If dispatch systems fail that has a safety risk to flight ops. While you may not be happy that your flight gets cancelled. For airline IT there is a cost vs benefit balance between the probability of flight cancellations vs the cost of having extra systems. (And in this case extra systems would probably have been affected by the same security platform, because not having that is another risk of cyber attack to consider) That doesn't apply to flight ops, where each operator needs to prove to a very high level that safety is always maintained. Maximum probability for catastrophic failure is 10E-9 and for hazardous is 10E-7. No commercial considerations considered, have to make those numbers to be allowed to operate.
- Ekaros 2y agoAirlines really aren't that big deal. Once you land and park a plane. Well not too much will happen. Only thing after dust settles is to reconcile maintenance records. Then again with systems working Boeing failed that one...
- BHSPitMonkey 2y ago> Once you land and park a plane. Well not too much will happen. Except for massive disruptions to tons of people, businesses, and economies worldwide, with impacts rippling out for days after services have been restored?
- smt88 2y agoYes, Dept. of Transportation is already investigating Delta[1]. 1. https://www.npr.org/2024/07/23/nx-s1-5049792/deltas-airlines-delays-and-cancelations-prompt-dot-investigation https://www.npr.org/2024/07/23/nx-s1-5049792/deltas-airlines...
- TeMPOraL 2y agoI don't think "CS are idiots and use their kernel-level trojan to accidentally crash every Windows computer it's running on across the whole world" was ever on anyone's threat board[0]. Maybe they have considered IT outage of their own systems, but this wasn't that - this hit everyone all at once. Should hospitals plan on not being able to provide medical care and not able to transfer their patients elsewhere, or divert the inflow of new patients elsewhere, because every other hospital is down too, there is no one left to provide care, and 911 is shot anyway? Maybe. Right after planning for a nuclear explosion over the city. What happened was pretty much an "act of God"-level crisis, except caused by a de-facto infrastructure provider with way more destructive power than they're equipped to handle. IMO, not only CrowdStrike should be liable for the damage and lives lost because of the outage, this incident should be a prompt to rethink the entire idea of endpoint security. -- [0] - I think it should be, but then I think the entire business with endpoint protection is bullshit.
- MyFedora 2y ago> I don't think "CS are idiots and use their kernel-level trojan to accidentally crash every Windows computer it's running on across the whole world" was ever on anyone's threat board. No, but cyberattack takes out all computer infrastructure is a high impact, low risk that critical infrastructure providers must account for and would've prevented any impact from CrowdStrike's blunder. They obviously didn't do that.
- SebFender 2y ago"this incident should be a prompt to rethink the entire idea of endpoint security" Yes.