SIGforum
BREAKING: Mass worldwide IT outage hits airlines, media and banks

This topic can be found at:
https://sigforum.com/eve/forums/a/tpc/f/320601935/m/1760008905

July 19, 2024, 10:54 AM
radioman
BREAKING: Mass worldwide IT outage hits airlines, media and banks
quote:
Originally posted by r0gue:
.........Crowdstrike is a leading cybersec vendor of software and services.

"American Airlines says Crowdstrike, a cybersecurity company, is the source of the tech issues."



Add Crowdstrike to the growing list of companies run by morons.


.
July 19, 2024, 10:54 AM
architect
A quick Ducky search reveals some facts about this situation. The problem is, apparently, with a CrowdStrike product named "Falcon." Falcon is a daemon that is intended to detect and respond to threats against the system. My speculation is that the new revision got a little over-eager and detected a false positive system compromise, and responded by locking down the system resulting in a BSoD. In other words, it did what it was supposed to do, only too much so.

Of course, it certainly is possible that all those affected systems actually did have some sort of malware already present on them, and were waiting for a bad actor to activate them en masse, potentially resulting in a much worse event.

The real issue is the near uniformity of installed OS (Windows) and security software (Crowdstrike Falcon) in the business community. The impetus to install the "market leading" software results in a self-reinforcing situation where everybody becomes vulnerable to the same attack, greatly simplifying an attacker's job. System administrators responsible for significant assets would do well to learn from this situation and base their infrastructures going forward on non-mainstream systems, or at least have a backup system in place that works differently from the production system.
July 19, 2024, 10:55 AM
konata88
Honest mistake? (doubtful)

Incompetence? (possible)

DEI? (probable)




"Wrong does not cease to be wrong because the majority share in it." L.Tolstoy
"A government is just a body of people, usually, notably, ungoverned." Shepherd Book
July 19, 2024, 11:32 AM
Georgeair
While Amazon is up, their customer support is not.

I bit of a disruption in F1 practice earlier. Not the sponsor image you're hoping to be in circulation.....





You only have integrity once. - imprezaguy02

July 19, 2024, 11:42 AM
Veeper
This just happened to us a few months ago. Crowdstrike errantly identified a Windows system file as malicious and sent the Windows systems into bluescreen cycles and eventually, by design, into Bitlocker lockdown mode.

The fact that heads didn’t roll when this happened a few months ago, leads me to believe that there should be a larger swath of firings this time around.

This is (probably) not anything to get into a frenzy about, other than to hopefully wake people up to the lack of control we have when everything is SaaS-controlled due to the “cost savings” of running lean.

Crowdstrike is just like every other garbage AV company in that they will happily take your money, while creating a shittier product over time.




“The urge to save humanity is almost always only a false-face for the urge to rule it.”—H.L. Mencken
July 19, 2024, 11:45 AM
soflaac
This reminds me of the time a video game that I played offered a new patch for download. Problem with it is that they were deleting their boot.ini file within the game files, unfortunately the code deleted the individual user Windows boot.ini file and when they restarted their pc........bricked.

(Eve Online - 2007)

https://www.eveonline.com/news...t-the-boot.ini-issue

Of course the company downplayed the error. Frown



<><
America, Land of the Free - because of the Brave
July 19, 2024, 11:45 AM
Vgex
Catastrophic where I am. Live update/cloud based software is the worst.
July 19, 2024, 12:04 PM
sse
my kid's flying around Europe for the next few days, hope she doesn't get caught up in it too much.
July 19, 2024, 12:07 PM
cyanide357
Lesson 1: Don’t run business/mission critical systems on Windows.

Lesson 2: Don’t connect critical infrastructure systems to the internet. Just in general, but not specifically an issue in this event. Update with the poison file (invalid format in this case) came through the official channel.

Of course the current mantra in IT with Agile / DevSecOps is “Move fast and break things”. Also puts the whole thing about how software is eating the world into a different perspective.
July 19, 2024, 12:16 PM
Chowser
It hit us at work sometime after midnight. 911 went down. Computers went down.

I'm not the IT person but I kept getting calls. I was 550 miles away on vacation. I told them to call the IT people we pay monthly to fix it.

Anyways, I get to work today at 9:30 after driving 6 hours and get to work to fix stuff (while I'm still on vacation till Monday) that the IT company couldn't, and I got written up for something that happened a week ago and suspect didn't even complain. Just a coworker who read a report and said I violated some taser policy which we don't have one.

smh



Not minority enough!
July 19, 2024, 12:22 PM
parabellum
SIGforum is up.

Namaste
July 19, 2024, 12:31 PM
sigmonkey
Good news.

All nine the countries with nuclear weapons use CrowdStrike's Falcon EDR...




"the meaning of life, is to give life meaning" Ani Yehudi אני יהודי Le'olam lo shuv לעולם לא עוד
July 19, 2024, 12:40 PM
Leemur
Sounds about as secure as the secret service
July 19, 2024, 12:41 PM
parabellum
Class?
July 19, 2024, 12:45 PM
Shaql
Now imagine your pc is bricked and all of your money was tied up in the gov't CBDC!

Or worse, your CBDC was bricked.





Hedley Lamarr: Wait, wait, wait. I'm unarmed.
Bart: Alright, we'll settle this like men, with our fists.
Hedley Lamarr: Sorry, I just remembered . . . I am armed.
July 19, 2024, 12:59 PM
trapper189
quote:
Originally posted by parabellum:
Class?
Politics in an apolitical thread?
July 19, 2024, 01:03 PM
sigmonkey
quote:
Originally posted by Leemur:
...





"the meaning of life, is to give life meaning" Ani Yehudi אני יהודי Le'olam lo shuv לעולם לא עוד
July 19, 2024, 01:06 PM
parabellum
quote:
Originally posted by trapper189:
quote:
Originally posted by parabellum:
Class?
Politics in an apolitical thread?
Politics in an apolitical thread, yes, thank you.

Now, as I was saying, my TV remote control is functioning properly. Microwave, too.

I don't see the problem.
July 19, 2024, 01:58 PM
Tuckerrnr1



_____________________________________________
I may be a bad person, but at least I use my turn signal.
July 19, 2024, 02:00 PM
parabellum
Just tried my garage door. Goes up, goes down. Stops when I stop it. Starts when I start it.

I don't see the problem