4 ms·
I haven't seen a postmortem or RCA from Crowdstrike yet. Do you work there?
by ttymck 2y ago
I haven't seen a postmortem or RCA from Crowdstrike yet. Do you work there?
- jhardy54 2y ago> I haven't seen a postmortem or RCA from Crowdstrike yet. I got you! It’s relatively new, published four days ago. The relevant section is called “what went wrong and why”: https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/ https://www.crowdstrike.com/falcon-content-update-remediatio...
- Spooky23 2y agoThere’s a lot of fluff, that boils down to “we tested the code in march”, “we did not test subsequently”, “we validate the content we push”, and “there was a defect in the content validation process”
- ttymck 2y agoAnd it seems to confirm, although not completely explicit, that there was _not_ a canary facility in place.
- Spooky23 2y agoCorrect. It sounds like they test changes to code in such a facilty, but “content” is only validated by a parser. Mcafee did something similar a decade ago. It’s a hard problem - the whole point of Crowdstrike is to quickly respond to threats. (And they are very good at it) So you want time to market for marginal changes to be very fast. Normally I’d give them the benefit of the doubt, but their arrogance and poor response triggers my spidey-sense.
- ttymck 2y agoThank you! I'm surprised this didn't get more coverage in my social media sphere. I'm still seeing memes and jokes.
- ncr100 2y agoMS just provided theirs, it's a bad architecture issue where CS overused the kernel mode, and should have instead done a listener in the kernel and logic in User land.