Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kchr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
kchr
2y ago
The limitations of old game platforms didn't vanish, they are still used (and being re-discovered by new generations). One of my favorite games on this side of the new millennium is Celeste, for example. Some indie studios are even pro
32.
▲
by
kchr
2y ago
Yeah, WinPE media tools have been around for years. Here is an article from 2021 (although it has been a thing long before then): https://learn.microsoft.com/en-us/windows-hardware/manufactu... Still, customizing
33.
▲
by
kchr
2y ago
Yes, but it's not included in the upstream Ubuntu security repository. In fact, it's not available via any repository AFAIK. It updates itself via fetching new versions from CrowdStrike backend according to your update policy for
34.
▲
by
kchr
2y ago
Ubuntu LTS has support for 5 years, can be extended to 10 years of maintenance/security support with ESM (which is a paid service). Same with Rocky Linux, but the extra 5 years of maintenance/security support is provided for free.
35.
▲
by
kchr
2y ago
Some comments theorise that the NUL-file was deployed to fix the issue with the corrupt file that caused the crashes.
36.
▲
by
kchr
2y ago
CrowdStrike uses eBPF on Linux and System Extensions on macOS. Neither if which need kernel level presence. Microsoft should move towards offering these kind of solutions to make AV and EDR more resistent on Windows devices, without jeopard
37.
▲
by
kchr
2y ago
> Detecting system crashes would be hard. Store something like an `attemptingUpdate` flag before updating, and remove it if the update was successful. Upon system startup, if the flag is present, revert to the previous config and mark th
38.
▲
by
kchr
2y ago
Absolutely, training is key. Alas, managers don't seem to want their employees spending time on anything other than delivering profit and so the training courses are zipped through just to mark them as completed. Personally, I don'
39.
▲
by
kchr
2y ago
I totally agree. In my current work environment, we do deploy EDR but it is primarily for assets critical for delivering our main service to customers. Ironically, this incident caused them all to be unavailable and there is for sure a less
40.
▲
by
kchr
2y ago
I'm curious, what did your deployment plan look like? Phased/staggered, if so how?
41.
▲
by
kchr
2y ago
A good reminder of the fact that your Thursday might be someone else's Friday.
42.
▲
by
kchr
2y ago
The file extension is `sys` by convention, it's nothing magical to it and it's not handled in any special way by the OS. In the case of CrowdStrike, there seems to be some confusion as to why they use this file extension since it&
43.
▲
by
kchr
2y ago
Which also explains why they, only if needed to cover their back legally, confirm or deny details being shared on social and mass media.
44.
▲
by
kchr
2y ago
> Many of the companies have Crowdstrike enabled and automatic updates turned on to check some audit box. They have to keep the updates going out regularly. While many companies probably do that, it's usually not required if you can
45.
▲
by
kchr
2y ago
My experience is that in these workplaces where EDR is enforced on all devices used for work, your hypothetical is true (i.e. you are not expected to work on devices not provided by your employer - on the contrary, that is most likely forbi
46.
▲
by
kchr
2y ago
Most AV and EDR solutions support exceptions, either on specific assets or fleets of assets. You can make exceptions for some employees (for example developers or IT) while keeping (sane) defaults for everybody else. Exceptions are usually
47.
▲
by
kchr
2y ago
This. From all the comments I've seen in the multiple posts and threads about the incident, this simple fact seems to be the least discussed. How else to protect a complex IT environment with thousands of assets in form of servers and
48.
▲
by
kchr
2y ago
Highly unlikely anyone except governments or top-paying corporations with custom-negotiated T&Cs will see a detailed post-portem, unless someone blows the whistle. Would love to read an AmA.
49.
▲
by
kchr
2y ago
It is untrusted data in the sense of files being read from disk that are not part of the signed kernel driver code.
50.
▲
by
kchr
2y ago
I suspect that regardless of which country CrowdStrike is from, the question would still arise: "should we really outsource information security protection of our critical infrastructure to country X?" Naturally, the question of m
51.
▲
by
kchr
2y ago
> Some sort of sand box for all these kernel access Yeah, like eBPF in Linux or System Extensions in macOS.
52.
▲
by
kchr
2y ago
Instead of calling out AV/EDR solutions as malware and spyware, I have a better solution: Stop using your workstations for private stuff. They belong to the company, and they are a liability since you use them to access the company env
53.
▲
by
kchr
2y ago
Last time I checked, CS primarily runs in kernel mode on Linux and only fall back to eBPF if the kernel version is not supported. When in eBPF mode, they call it "Reduced Functionality Mode (RFM)". Has this changed?
54.
▲
by
kchr
2y ago
Escape Goat!
55.
▲
by
kchr
2y ago
CS doesn't force you to auto-upgrade the sensor software – there is quite some FUD thrown around at this moment. It's a policy you can adjust and apply to different sets of hosts if needed. Additionally, you can choose if you wa
56.
▲
by
kchr
2y ago
Using it and loving it. Security aspects aside, it's also the best tool I've tried for proper asset management in multi-cloud scenarios. With the graph feature you can write queries for basically anything, across all accounts if y
57.
▲
by
kchr
2y ago
You debug it with shellcheck[0] and `set -ex` (which will trace each statement on STDOUT). [0] https://www.shellcheck.net/
58.
▲
by
kchr
2y ago
NameISP does this. Auto-renewal and payment by invoice.
59.
▲
by
kchr
2y ago
What you are describing is a forwarding DNS query resolver, which can be configured to directly answer queries without forwarding them upstream in the DNS hierarchy. This is sometimes used for ad-blocking, but the archetypical example is th
60.
▲
by
kchr
2y ago
Not to mention All-Seeing Eye!
More ›