andythebrave
Member
Or, especially, Frank.Only if you're called Dave![]()
Or, especially, Frank.Only if you're called Dave![]()
Zscaler is focused more on external network access from an organisation.Whatever the MS problem overnight was, it was fixed quickly. Went online for work at 7.30am, and no hint of any issues. Our (non railway) company uses zScaler for cyber security, so business as usual today.
The BBC have found a greybeard who seems to know his stuff. The rest are, as you suggest, not much use.
He's who I thought of when I saw that post too. That interview showed just how pointless most 24 hours news filler discussions are, that someone with no experience of live TV could improvise like that without serious issue.Where's Guy Goma when we need him?
It's grim to say the least. Lots of uninformed blame going towards Microsoft but this is definitely a Crowdstrike problem and I'm actually wondering how long they'll continue to exist. CRWD stock down over 20% in out-of-hours trading.
And even more. I don't know anything about deployment but this is commercial software (for businesses mostly I think) so you would think at least that following internal testing you would release updates to a small number of commercial customers and then do the full update a few days later. This seems to have hit all at once (albeit a small fraction of a huge customer base can still be a lot). Still waiting for the real details however so still a bit of speculation.Once the lawyers are wheeled out I'd be amazed if this doesn't kill the company.
Of course there's probably no established IT person who hasn't at some point mucked up a production system and had to work late to fix it - I certainly have. However this one is a bit consequential and so there should have been multiple checks before it got into the wild.
There is plenty of appetite to understand the root cause of this bad code getting out. Personally I'd like to know how the cost of these global outages will stack up against the running costs of the malware Crowdstrike is designed to prevent. Could the medicine cost more than the disease?Of course there's probably no established IT person who hasn't at some point mucked up a production system and had to work late to fix it - I certainly have. However this one is a bit consequential and so there should have been multiple checks before it got into the wild.
I thought that immediately, why send this "update" to the whole world without real-time testing first? Selected customers could be "paid" to be guinea-pigs - a beta model? - to ensure safe passage of the update when brought out worldwide.And even more. I don't know anything about deployment but this is commercial software (for businesses mostly I think) so you would think at least that following internal testing you would release updates to a small number of commercial customers and then do the full update a few days later. This seems to have hit all at once (albeit a small fraction of a huge customer base can still be a lot). Still waiting for the real details however so still a bit of speculation.
Speed and ease of release is a key part of the offering of these types of software, precisely to ensure they are able to prevent attacks as soon as possible. Many companies will be asking if the cure is costing them more than the threat today.I thought that immediately, why send this "update" to the whole world without real-time testing first? Selected customers could be "paid" to be guinea-pigs - a beta model? - to ensure safe passage of the update when brought out worldwide.
Have they tried switching it off and switching it back on again?
Have they tried switching it off and switching it back on again?
You really think they were being serious?The solution is only a little more complex than that and already posted on this thread.
That is a good point. However it just means you need to separate thread definition/detection and make that super robust from other aspects you might update which may be higher risk.Speed and ease of release is a key part of the offering of these types of software, precisely to ensure they are able to prevent attacks as soon as possible. Many companies will be asking if the cure is costing them more than the threat today.
Or we could try drilling to the Earth's core and finding the "Press to restore the Earth's factory settings" button.Have they tried switching it off and switching it back on again?
You really think they were being serious?
though one of the buzzwords in the industry is about how all testing should be automated for speed and reliability - I suspect there'll be a lot of questions to be asked as to how much testing and validation was done. given the scale it'd be hard to suggest that it was a niche bug that is only triggered in specific circumstances!Speed and ease of release is a key part of the offering of these types of software, precisely to ensure they are able to prevent attacks as soon as possible. Many companies will be asking if the cure is costing them more than the threat today.
Yes, clearly.
![]()
CrowdStrike file update bricks PCs around the world
Updated: Falcon Sensor putting hosts into deathloop - but there's a workaroundwww.theregister.com
It is hardly the most difficult concept that removing part of the faulty program (or deleting the whole thing but a dev from the company behind it aren't going to advise that are they) will solve the issue.
That's why you boot into safe mode, that's fairly trivial to do on a consumer machine or a corporate machine that isn't locked down. But many will be very heavily locked down meaning an IT technician is almost certainly going to need to visit the site of the machine to get around the corporate security put in place to prevent someone from booting into safe mode.The problem is - if your PC crashes, then you cant get into it to find out how to solve the problem!!
The problem is - if your PC crashes, then you cant get into it to find out how to solve the problem!!
Appears to be Windows 10, I'm running Windows 11 on my main all-in-one (all-in-one as in if one thing crashes it all does) but stlll running good old Windows 7 on my PC upstairs. Is this purely a W10 problem? When I last went to my local computer shop, they offered me a re-conditioned Windows XP for about £50!!
Tempted!!
Almost certainly just corporate and only those who have Crowdstrike software installed. Most consumers either will be using Windows Defender or one of the other big anti-virus/malware providers like McAfee, Norton, Avast or Malwarebytes.Does anyone know if this is generally affecting domestic PC's or just corporates ?
It can affect any PC which has the Crowdstrike software installed. That said, it's unlikely many domestic PC's will have it.Does anyone know if this is generally affecting domestic PC's or just corporates ?
Almost certainly just corporate and only those who have Crowdstrike software installed. Most consumers either will be using Windows Defender or one of the other big anti-virus/malware providers like McAfee, Norton, Avast or Malwarebytes.
It can affect any PC which has the Crowdstrike software installed. That said, it's unlikely many domestic PC's will have it.
That's why safe mode boot is required.The problem is - if your PC crashes, then you cant get into it to find out how to solve the problem!!
You really think they were being serious?