3 ms·
Security software is often an security nightmare by itself. The amount of vulnerabilities you see in the products themselves is worrying. They try to offer prot
by ManBeardPc 2y ago
Security software is often an security nightmare by itself. The amount of vulnerabilities you see in the products themselves is worrying. They try to offer protection but create a new huge attack vector directly inside the kernel with full permissions. Not even talking about the huge performance hit and the many false positives. IMHO way too much risk/inconvenience and too little benefits to be worth it.
- gmac 2y agoYes, Crowdstrike is yet another opportunity to feel vindicated that (when I was a CTO) I made sure our information security policies mandated people to use only the macOS/Windows built-in AV tools.
- hpeter 2y agoIf you want security, use a secure OS. But it's not so easy, often decisions are made not to have the best technical solution, but to fulfill business agreements.
- smt88 2y agoWhile often true, this entire comment is completely unrelated to this issue or article. The CrowdStrike failure was an issue of quality control, not susceptibility to an attack.
- ManBeardPc 2y agoThe position inside the kernel played a big part in making the incident worse and this part is mentioned in the article. Questioning the need for putting software there and what we could change on the technical side should be part of the discussion.
- SebFender 2y agonamed pipes aren't kernel level.
- bdjsiqoocwk 2y agoThis is a subject I know nothing about. If it's known that the kernel has security flaws, why aren't they fixed? Or is it that this company is aware of specific security flaws that no one else is?
- noisem4ker 2y agoThey claim to detect anomalous program behavior within otherwise perfectly legal use of the operating system APIs.