• Carighan Maconar@lemmy.world
    link
    fedilink
    arrow-up
    135
    ·
    4 months ago

    And keep in mind, the falcon sensor exists for Linux. All those big companies largely use it.

    Essentially we just got lucky that their buggy patch only affected the windows version of the sensor in a showstopping way. Could have been all major OS.

    • Fonzie!@ttrpg.network
      link
      fedilink
      arrow-up
      6
      ·
      4 months ago

      The issuw didn’t affect Linux and macOS systems with Crowdstrike Falcon installed, though, only Windows systems.

      On Windows, booting into Safe Mode and removing C:\Windows\System32\Drivers het bestand C-00000291*.sys temporarily solves the BSOD issue, as well.

      • Brkdncr@lemmy.world
        link
        fedilink
        arrow-up
        24
        ·
        4 months ago

        The point is that it could have. Or maybe some unknown 0-day gets used by someone out to cause chaos instead of collect random.

        • Fonzie!@ttrpg.network
          link
          fedilink
          arrow-up
          9
          ·
          4 months ago

          That’s true

          On one hand I hope people are smart enough to run updates to critical systems on a test environment, first. On the other hand I’ve learned that that is not at all the case yesterday.

          • Brkdncr@lemmy.world
            link
            fedilink
            arrow-up
            11
            ·
            4 months ago

            Many security products have no test option. One I’m using has a best practice of a 15 minute delay between test and prod and no automation to suspend besides relying on the vendor to pull the update it within 15 mins if it were to go full crowdstrike.

    • 1984@lemmy.today
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      4 months ago

      I don’t think the Linux culture is very similar to the windows culture. At least for me personally, I wouldn’t use crowdstrike and let them install whatever they want into my environment.

      Maybe it’s just me.

      • Carighan Maconar@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        4 months ago

        It’s not your machine, your choice of distro, or your choice of specific packages to use or not use. It’s a work tool you get handed as part of a job. So whether CrowdStrike runs on it or not is not your decision and you aren’t allowed (and usually not capable) to change that.

        That’s an entirely different situation from one where you get a PC to do with as you please and set up yourself, or a private machine.

        Plus we’re mostly talking endpoint devices for non-technical users with many of these difficult-to-fix devices as techs have to drive out to them. The users expect a tool, and they get a tool. A Linux would be customized and utterly locked down, and part of that would be the endpoint protection software.