GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 25-Jul-2024 08:21:01 JST Kevin Beaumont Kevin Beaumont

    If you want to know something crazy:

    - This year TCS migrated their EDR to CrowdStrike
    - Then they announced a strategic partnership with CrowdStrike
    - Then they lost all their systems
    - They’re just finishing recovery today, 6 days in
    - Then they got a $10 Uber Eats voucher
    - …which got cancelled due to Uber flagging CrowdStrike’s account as fraudulent

    In conversation about 10 months ago from cyberplace.social permalink

    Attachments


    1. https://cyberplace.social/system/media_attachments/files/112/844/027/247/632/597/original/4d9f0e8aa975fb10.png

    2. https://cyberplace.social/system/media_attachments/files/112/844/027/700/774/861/original/390207ecbd025b60.png

    3. https://cyberplace.social/system/media_attachments/files/112/844/028/023/080/879/original/cf26546376451da8.jpeg
    • Embed this notice
      Richard (richards@fosstodon.org)'s status on Thursday, 25-Jul-2024 09:19:17 JST Richard Richard
      in reply to

      @GossiTheDog oh my god the $10 gift card is real? I honestly thought that was just a joke floating around. I feel like a $10 “sorry” is worse than nothing at all.

      In conversation about 10 months ago permalink
    • Embed this notice
      Kevin Burns (burnskp@hachyderm.io)'s status on Thursday, 25-Jul-2024 17:27:05 JST Kevin Burns Kevin Burns
      in reply to

      @GossiTheDog wait the Uber eats thing wasn’t a joke?

      In conversation about 10 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 25-Jul-2024 17:41:09 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CrowdStrike are… having a week.

      In conversation about 10 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/846/230/546/593/661/original/f194089e34cc7e28.jpeg
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 25-Jul-2024 18:13:49 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Questions for your EDR providers (do not assume they are experts in availability):

      - What are your different update processes?
      - How do you test them?
      - Do you dogfood test them?
      - Do you roll them out in waves? What are the details, eg what percentages and when?
      - Do you monitor failures and roll back?

      In conversation about 10 months ago permalink
      GreenSkyOverMe (Monika) repeated this.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 25-Jul-2024 22:59:22 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CrowdStrike staff members are selling CrowdStrike monopoly sets they were given on eBay.

      In conversation about 10 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/847/480/206/685/298/original/c9b438c0b762fb5c.jpeg

      2. https://cyberplace.social/system/media_attachments/files/112/847/480/457/995/977/original/f5d9fc315043c0cb.jpeg

      3. https://cyberplace.social/system/media_attachments/files/112/847/480/744/267/639/original/4a4e76c54de324ef.jpeg
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 26-Jul-2024 08:10:28 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CrowdStrike filed at 8-K with the SEC on July 22nd for a cybersecurity incident. https://www.board-cybersecurity.com/incidents/tracker/20240722-crowdstrike-holdings-inc-cybersecurity-incident/

      In conversation about 10 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.board-cybersecurity.com
        2024-07-22 CrowdStrike Holdings, Inc. Cybersecurity Incident
        CrowdStrike Holdings, Inc. initially disclosed a cybersecurity incident in an SEC 8-K filing on 2024-07-22 17:27:44 EDT. Company Summary Incident Details Filings 8-K filed on 2024-07-22 Company Information Company Summary CrowdStrike is a cybersecurity technology firm that provides cloud-delivered protection for cloud workloads, identity, and data. Incident Details Material: Unknown Is Breach: Unknown Records Compromised: Unknown Data Types Impacted: No Data Types Tracked (yet) Compromised Date: Detected Date: 2024-07-19 Disclosure Date: 2024-07-22
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 26-Jul-2024 08:11:51 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Almost a week in, CrowdStrike say 97% of devices are back online. https://www.axios.com/2024/07/25/crowdstrike-97-percent-systems-online

      In conversation about 10 months ago permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 26-Jul-2024 20:13:05 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Microsoft are talking about changes to Windows after the CrowdStrike incident. Good.

      https://www.theverge.com/2024/7/26/24206719/microsoft-windows-changes-crowdstrike-kernel-driver

      In conversation about 10 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.theverge.com
        Microsoft calls for Windows changes and resilience after CrowdStrike outage
        from Tom Warren
        Microsoft drops subtle hints about the future direction of Windows security.
    • Embed this notice
      Chris Adams (acdha@code4lib.social)'s status on Saturday, 27-Jul-2024 04:08:32 JST Chris Adams Chris Adams
      in reply to
      • SecureWaffle🧇

      @SecureWaffle @GossiTheDog They _must_ do that if they want to sell Windows in Europe, where they have a requirement that third-parties get the same access as their own security products do.

      This is healthy in a way: if the kernel & Defender teams work out what it'd take for the latter to run in user space, I'd bet that MVP API would cover most other users with minimal additions since they all care about the same kinds of activities.

      In conversation about 10 months ago permalink
    • Embed this notice
      SecureWaffle🧇 (securewaffle@twit.social)'s status on Saturday, 27-Jul-2024 04:08:33 JST SecureWaffle🧇 SecureWaffle🧇
      in reply to

      @GossiTheDog
      I wonder if Microsoft will move their own Defender/ATP out of kernel. Will they next remove their defender/ATP from needing to run in the Linux kernel?

      In conversation about 10 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 30-Jul-2024 08:00:43 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • Alex Stamos
      • Patrick Gray

      There’s a really good discussion on @riskybusiness’s YouTube show about the CrowdStrike incident.

      About the 3 minute mark @alex made me realise I was far too kind to CrowdStrike. He rightly rips them apart.

      https://youtu.be/EGRqtscp4eE

      In conversation about 10 months ago permalink

      Attachments

      1. Why CrowdStrike's Baffling BSOD Disaster Was Avoidable
        from Risky Business Media
        Risky Business host Patrick Gray talks to SentinelOne's Chris Krebs and Alex Stamos about CrowdStrike's baffling failure and what it means for the wider secu...
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 30-Jul-2024 19:28:20 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • boB Rudis 🇺🇦 🇬🇱 🇨🇦

      Delta are looking to sue CrowdStrike and Microsoft. HT @hrbrmstr

      https://www.cnbc.com/2024/07/29/delta-hires-david-boies-to-seek-damages-from-crowdstrike-microsoft-.html

      In conversation about 10 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: image.cnbcfm.com
        Delta hires David Boies to seek damages from CrowdStrike, Microsoft after outage
        from https://www.facebook.com/CNBC
        Delta has hired prominent attorney David Boies to pursue potential damages from CrowdStrike and Microsoft after a mass outage earlier this month.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 30-Jul-2024 21:14:59 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Re the Delta case - the lawyer they’ve hired successfully sued Microsoft previously on behalf of the US government, and the decision was upheld on appeal too. The ruling almost lead to the breaking up of Microsoft.

      The following US government backed out of the case.

      Bill Gates said at the time the lawyer was “out to destroy Microsoft”.

      So there’s a chance here the CrowdStrike incident may end up having implications across vendor industry around warranties etc, we’ll see.

      In conversation about 9 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 31-Jul-2024 00:10:35 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Jim Cramer does it again.

      In conversation about 9 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/876/073/001/828/039/original/70c2957022f94e91.jpeg

      2. https://cyberplace.social/system/media_attachments/files/112/876/073/390/785/490/original/0cf74769d4c74dfb.jpeg
    • Embed this notice
      Norbert Kowallik (nkow14@social.anoxinon.de)'s status on Wednesday, 31-Jul-2024 00:57:16 JST Norbert Kowallik Norbert Kowallik
      in reply to

      @GossiTheDog honestly, that’s what I expected. I‘m really looking forward to the first meeting with our crowdstrike technical advisors after the vacation. And I’m wondering what our management will decide about our future with crowdstrike, my guess is… we‘ll keep them and try to negotiate something regarding license renewal.

      In conversation about 9 months ago permalink
    • Embed this notice
      Jason Haar :laserkiwi: (jhaar@mastodon.nz)'s status on Wednesday, 31-Jul-2024 01:28:22 JST Jason Haar :laserkiwi: Jason Haar :laserkiwi:
      • Norbert Kowallik

      @GossiTheDog @nkow14 migrate to what? They are pretty good...

      In conversation about 9 months ago permalink
    • Embed this notice
      Maxi 10x 💉 (frumble@chaos.social)'s status on Wednesday, 31-Jul-2024 06:00:40 JST Maxi 10x 💉 Maxi 10x 💉
      in reply to

      @GossiTheDog The PC emulator for iOS?!

      In conversation about 9 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 31-Jul-2024 19:16:05 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Replacing an XDR platform at scale takes some time, so if you’re wondering what the translation of Elon’s tweet about Crowdstrike is:

      Elon: can we replace Crowdstrike?
      Somebody: yes, we’ll begin looking into it but..
      Elon: job done

      In conversation about 9 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/880/578/250/201/208/original/923dd00529a11fb3.jpeg
      Haelwenn /элвэн/ :triskell: likes this.
      GreenSkyOverMe (Monika) repeated this.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 31-Jul-2024 23:02:28 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Delta’s CEO has confirmed they plan to take legal action against CrowdStrike after incurring a $500m loss https://www.ft.com/content/dba1cb7a-46b1-4f94-b596-432e7d899f8d

      In conversation about 9 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: spoor-api.ft.com
        Subscribe to read
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 01-Aug-2024 16:27:05 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CrowdStrike shareholders are suing CrowdStrike https://www.bbc.com/news/articles/cy08ljxndr4o

      In conversation about 9 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: ichef.bbci.co.uk
        CrowdStrike: Tech firm sued by shareholders over IT global outage
        A faulty update by the cyber-security firm last month caused chaos around the world.
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 01-Aug-2024 16:41:36 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CrowdStrike made a net loss of $845m between 2018 until this year.

      In conversation about 9 months ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 01-Aug-2024 21:24:54 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Spirit Airlines in the US anticipates a $7.2 million hit to its third-quarter operating income due to operational disruptions caused by the CrowdStrike incident, which forced the carrier to cancel 470 flights.

      In conversation about 9 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 02-Aug-2024 03:13:52 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Here's the Delta boss on his thoughts about the CrowdStrike incident.

      They had 40k Windows Server boxes alone, all with BitLocker full disk encryption enabled, all of which wouldn't boot and weren't fixable without manually unlocking BitLocker. That had gone all in with CrowdStrike + Microsoft's most premium offerings.

      He has a really good point about how tech companies have become obsessed with growth as their only metric of success, and customer satisfaction is not on the radar.

      In conversation about 9 months ago permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 02-Aug-2024 03:28:37 JST Kevin Beaumont Kevin Beaumont
      in reply to

      There's a really mad moment in that interview where they ask them what assistance CrowdStrike have offered, and he essentially says nothing, not even a lunch voucher.

      What a time to be alive.

      In conversation about 9 months ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Glen Arrowsmith (garrows@bne.social)'s status on Friday, 02-Aug-2024 05:43:00 JST Glen Arrowsmith Glen Arrowsmith
      in reply to

      @GossiTheDog 40k Window servers??? That doesn't make sense! 4000 would be hard to believe. Why do they need so many?

      In conversation about 9 months ago permalink
    • Embed this notice
      Justin Scholz (jmovs@mastodon.social)'s status on Friday, 02-Aug-2024 06:52:56 JST Justin Scholz Justin Scholz
      in reply to

      @GossiTheDog “free consulting” 🤣

      In conversation about 9 months ago permalink
    • Embed this notice
      Glen Arrowsmith (garrows@bne.social)'s status on Friday, 02-Aug-2024 06:59:33 JST Glen Arrowsmith Glen Arrowsmith

      @GossiTheDog omg. Were they all sitting on <5% CPU utilization?

      In conversation about 9 months ago permalink
    • Embed this notice
      System Adminihater (systemadminihater@cyberplace.social)'s status on Friday, 02-Aug-2024 08:58:33 JST System Adminihater System Adminihater
      in reply to

      @GossiTheDog Its true. Tbey dont give a fuck whether anything works or not.

      In conversation about 9 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 03-Aug-2024 00:29:37 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CrowdStrike’s website then vs now

      In conversation about 9 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/893/134/034/079/028/original/bf13406cec3d11dc.jpeg

      2. https://cyberplace.social/system/media_attachments/files/112/893/134/759/551/848/original/0e436fd3e0814ae1.jpeg
      Haelwenn /элвэн/ :triskell: repeated this.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 03-Aug-2024 05:53:58 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CrowdStrike complained to Cloudflare about a CrowdStrike parody site… and Cloudflare took it down. Without a court order. https://clownstrike.lol/crowdmad/

      In conversation about 9 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: clownstrike.lol
        Clown Services Company - Unregistered Agent, Incompliance, Welfare, Debt Market, Analog, and Imaginary-Risk Solutions
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 03-Aug-2024 06:00:01 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Additionally to loop this in, CrowdStrike submitted a takedown for a parody label (they’ve since rescinded it after being called out).

      In conversation about 9 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/894/427/261/866/901/original/7638af20832cf4a3.png
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Saturday, 03-Aug-2024 06:52:24 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to

      @GossiTheDog FrEeZe PeAcH

      In conversation about 9 months ago permalink
    • Embed this notice
      Interpipes 💙 (interpipes@thx.gg)'s status on Saturday, 03-Aug-2024 07:41:16 JST Interpipes 💙 Interpipes 💙
      in reply to

      @GossiTheDog does 40k servers pass the sniff test or do they mean 40k devices?

      Because unless their servers should have had LOM, surely, and they only have ~100k staff total, many of whom would use shared endpoints (or not use one at all), so I can believe 40k endpoints.

      Even the most egregious example of unintegrated acquisitions I know of was only at around 10k servers (estimated!) for 50k employees, and Delta doesn’t really have a similar acqui-problem, do they?

      In conversation about 9 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 03-Aug-2024 15:16:10 JST Kevin Beaumont Kevin Beaumont
      in reply to

      We’ve reached the part of the brand cycle where people are using CrowdStrike as an excuse https://www.theverge.com/2024/8/2/24212298/mrbeast-beast-games-crowdstrike

      In conversation about 9 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.theverge.com
        MrBeast blames terrible Beast Games conditions on the CrowdStrike outage
        from Sean Hollister
        Contestants say food, water, prescription medicine and clean underwear were withheld — but the YouTuber is blaming external factors.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 03-Aug-2024 15:48:16 JST Kevin Beaumont Kevin Beaumont
      in reply to

      360 takes a look at the Crowdstrike kernel drivers - finds they implement an eBPF like system, contain a wide attack surface, don’t check validity of update files (eg no signing of updates) and claim they contain conditions for LPE and RCE vulnerabilities. https://mp.weixin.qq.com/s/uD7mhzyRSX1dTW-TMg4UhQ

      In conversation about 9 months ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        https://mp.weixin.qq.com/mp/wappoc_appmsgcaptcha?poc_token=HLLSrWajuA2SPtdYvjdXWf3LLSJuwuaSCpjIeMmK&target_url=https%3A%2F%2Fmp.weixin.qq.com%2Fs%2FuD7mhzyRSX1dTW-TMg4UhQ
      Fish of Rage repeated this.
    • Embed this notice
      Graham Sutherland / Polynomial (gsuberland@chaos.social)'s status on Saturday, 03-Aug-2024 19:36:21 JST Graham Sutherland / Polynomial Graham Sutherland / Polynomial
      in reply to

      @GossiTheDog also just writing it off as "the Chinese" is straight up fucking racism, there's literally 1.4bn people living there and treating them like a homogenous unit is fully bullshit

      In conversation about 9 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Sunday, 04-Aug-2024 06:22:23 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Previously on Crowdstrike Falcon vulnerability research, check out this timeline where they tried to use NDAs to avoid disclosure, then fixed it without telling anybody. https://modzero.com/modlog/archives/2022/08/22/ridiculous_vulnerability_disclosure_process_with_crowdstrike_falcon_sensor/index.html

      In conversation about 9 months ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor | mod%log
        We found a security related issue in most recent CrowdStrike Falcon Sensor. The bug itself is not worth a blogpost, as the severity is pretty low. However, we'd like to shed some light on a vulnerability submission and disclosure process with CrowdStrike: It was pretty weird.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 05-Aug-2024 05:25:18 JST Kevin Beaumont Kevin Beaumont
      in reply to

      EFF are calling for antitrust action after the CrowdStrike incident https://www.eff.org/deeplinks/2024/07/crowdstrike-antitrust-and-digital-monoculture

      In conversation about 9 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.eff.org
        CrowdStrike, Antitrust, and the Digital Monoculture
        from Rory Mir
        Last month’s unprecedented global IT failure should be a wakeup call. Decades of antitrust inaction have made many industries dangerously reliant on the same tools, making such crises inevitable. We must demand regulators break up the digital monocultures that are creating a less competitive, less...
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 05-Aug-2024 18:48:00 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Bloomberg report a vast majority of the CrowdStrike losses reported by customers will be judged by insurance as not covered by policies. https://www.bloomberg.com/news/articles/2024-08-02/billions-in-damages-from-crowdstrike-outage-to-go-uninsured

      In conversation about 9 months ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Bloomberg - Are you a robot?
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 05-Aug-2024 20:20:26 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CrowdStrike are publicly threatening their customer, Delta. https://www.theverge.com/2024/8/5/24213521/crowdstrike-refutes-blame-delta-outage-litigation

      In conversation about 9 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/909/141/486/505/098/original/ad4d68cb28daf721.jpeg
      2. Domain not in remote thumbnail source whitelist: www.theverge.com
        CrowdStrike says it’s not to blame for Delta’s days-long outage
        from Jess Weatherbed
        Delta allegedly declined offers to help restore its systems.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 05-Aug-2024 21:15:58 JST Kevin Beaumont Kevin Beaumont
      in reply to

      I've written up a bit about CrowdStrike's latest bold strategy.

      https://doublepulsar.com/crowdstrike-trying-to-use-legal-threats-to-suppress-criticism-and-parody-of-global-it-outage-49320e922120

      In conversation about 9 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 07-Aug-2024 02:03:24 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Microsoft have now queued up to try publicly throw their customer under the bus, claiming (without evidence) Delta’s CrowdStrike woes were due to non-Windows systems. The CrowdStrike issue only impacted Windows systems so I hope somebody at Microsoft knows what they are doing.

      https://www.theverge.com/2024/8/6/24214371/microsoft-delta-letter-crowdstrike-response-comments

      In conversation about 9 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.theverge.com
        Microsoft says Delta ignored Satya Nadella’s offer of CrowdStrike help
        from Tom Warren
        Delta repeatedly refused Microsoft’s offer of free help.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 07-Aug-2024 02:08:00 JST Kevin Beaumont Kevin Beaumont
      in reply to

      If anybody wants the subtext of what is happening here, CrowdStrike and Microsoft both really do not want to get sued by Delta and have it go to court as it would potentially be explosive for both orgs and the wider security industry.

      The customers are always plebs to be milked, as is status quo.

      In conversation about 9 months ago permalink
    • Embed this notice
      Alex (alex02@cyberplace.social)'s status on Wednesday, 07-Aug-2024 02:09:45 JST Alex Alex
      in reply to

      @GossiTheDog i hope they get the book thrown at them.

      In conversation about 9 months ago permalink
    • Embed this notice
      loucovey (loucovey@newsie.social)'s status on Wednesday, 07-Aug-2024 02:40:02 JST loucovey loucovey
      in reply to

      @GossiTheDog I was involved in another issue where an organization wanted to sue a couple of people for fraud. Their lawyers told them, "Well, the problem here is that your bookkeeping practices and approvals showed you knew exactly what was happening, so you would be held liable as well."
      That' is what would happen with Delta if they sued. Theyr own negligence contributed to the scale of the problem, after others had resolved it.

      In conversation about 9 months ago permalink
    • Embed this notice
      Guelfo Alexander Ghibellini (guelfoalexander@cyberplace.social)'s status on Wednesday, 07-Aug-2024 03:07:35 JST Guelfo Alexander Ghibellini Guelfo Alexander Ghibellini
      in reply to

      @GossiTheDog Microsoft was forced by law to open that segment of code to third parties. now they'll close it again and CrowdStroke will be resident in the BIOS/UEFI. And if they succeed, they will be resident in the physical Power Button. So they can also sell hardware.

      In conversation about 9 months ago permalink
    • Embed this notice
      System Adminihater (systemadminihater@cyberplace.social)'s status on Wednesday, 07-Aug-2024 03:12:46 JST System Adminihater System Adminihater
      in reply to

      @GossiTheDog Microsoft killed the Action Pack. That was the last straw. We ride at dawn.

      In conversation about 9 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 07-Aug-2024 19:33:33 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CrowdStrike incident root cause analysis is out.

      Overall, good… but.

      It is very verbose but doesn’t say much. Some of the wording will confuse people - eg it talks about rings (waves) in a way which makes you think it is already implemented. It isn’t. They’re saying they plan to implement it later.

      Channel updates weren’t tested on a real Windows PC prior to deployment, they relied on automated bespoke code testing. They don’t mention that and it’s the real reason.

      https://www.crowdstrike.com/wp-content/uploads/2024/08/Channel-File-291-Incident-Root-Cause-Analysis-08.06.2024.pdf

      In conversation about 9 months ago permalink

      Attachments



    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 07-Aug-2024 21:14:38 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Risky Business take on CrowdStrike root cause report is good.

      You can see the confusion the report provides in this discussion I think, eg some of the things are talked about as being implemented - but they’re down as findings for improvement. It’s the way the report is worded, to make you believe certain things existed.. that don’t yet.

      https://youtu.be/IcayaFA7OcI

      In conversation about 9 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/112/920/678/706/328/091/original/5cc47008920209cb.jpeg
      2. Risky Business episode 758 -- Crowdstrike's postmortem underwhelms
        from Risky Business Media
        On this week’s show, Patrick Gray and Adam Boileau discuss the week’s security news, including:* Crowdstrike talks loud in its postmortem, but says very litt...
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 08-Aug-2024 00:13:35 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Really good piece about CrowdStrike (technically CSC) misusing DMCA takedown notices over trademark disputes.

      CrowdStrike probably want to have a word with CSC about this and Cloudflare should tighten process as DMCA isn’t supposed to be used for this. I know CSC do it.. but they shouldn’t be.

      Wider point: cyber industry abusing process in takedowns.

      https://arstechnica.com/tech-policy/2024/08/parody-site-clownstrike-refused-to-bow-to-crowdstrikes-bogus-dmca-takedown/

      In conversation about 9 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: cdn.arstechnica.net
        Parody site ClownStrike refused to bow to CrowdStrike’s bogus DMCA takedown
        from @ashleynbelanger
        Parody site ClownStrike defended the "obvious" fair use.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 08-Aug-2024 22:35:39 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CrowdStrike have responded to two claimed vulnerabilities in CrowdStrike Falcon, including one made by a former staff member: https://www.crowdstrike.com/blog/tech-analysis-addressing-claims-about-falcon-sensor-vulnerability/

      There may be more to come on this one..

      In conversation about 9 months ago permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 09-Aug-2024 16:44:47 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CrowdStrike vs Delta vs Microsoft continues to play out in public, now SEC filings

      https://www.reuters.com/business/aerospace-defense/delta-air-warns-380-mln-revenue-hit-crowdstrike-outage-2024-08-08/

      In conversation about 9 months ago permalink

      Attachments


Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.