CrowdStrike Crashing / Seizing was Windows Fault!

There was a real, reproducible era where simply having crowdstrike installed could cause Windows to Blue screen of death (with or without ECC RAM)!

8 million windows computers saw Windows almost instantly crash by doing nothing other than simply having Crowdstrike installed, and downloading the signatures

This happened because instead of exercising caution with kernel modules and proper auditing by Microsoft and the crowdstrike team, Crowdstrike rushed through multiple signature updates a day.

This is the risk of normalising kernel modules with deep integration into the kernel which updates their behaviour multiple times a day and persisting the new behaviours. Furthermore, as it was likely closed source (even to Microsoft), only basic testing could likely be performed.

The only solution was to open Safe Mode and manually remove the dodgy signature.

Could we argue this is a bit more critical than a library causing issues for VLC on: https://lemmy.world/post/50098276 ? Probably... I'm unaware of 8.5 million Linux computers (or servers) dropping offline simultaneously from a single update

7 points · 0 comments · view on lemmy.world

0 Comments

No comments yet.