home.social

#crowdstroke — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #crowdstroke, aggregated by home.social.

fetched live
  1. I barely dodged the #CrowdStroke during my trip, only to get my train delayed by arsons for my return.

    At least the latter is fucking up the JOs so it's not all bad :blobfoxfloofexplode:

  2. I barely dodged the #CrowdStroke during my trip, only to get my train delayed by arsons for my return.

    At least the latter is fucking up the JOs so it's not all bad :blobfoxfloofexplode:

  3. I barely dodged the #CrowdStroke during my trip, only to get my train delayed by arsons for my return.

    At least the latter is fucking up the JOs so it's not all bad :blobfoxfloofexplode:

  4. After the gift card fiasco just took it to a whole new level, you might need an update on where we are with #CrowdStroke. Well do we have the video for you, or what:
    captiongenerator.com/v/2302333

  5. After the gift card fiasco just took it to a whole new level, you might need an update on where we are with #CrowdStroke. Well do we have the video for you, or what:
    captiongenerator.com/v/2302333

  6. After the gift card fiasco just took it to a whole new level, you might need an update on where we are with #CrowdStroke. Well do we have the video for you, or what:
    captiongenerator.com/v/2302333

  7. After the gift card fiasco just took it to a whole new level, you might need an update on where we are with #CrowdStroke. Well do we have the video for you, or what:
    captiongenerator.com/v/2302333

  8. After the gift card fiasco just took it to a whole new level, you might need an update on where we are with #CrowdStroke. Well do we have the video for you, or what:
    captiongenerator.com/v/2302333

  9. [long post] #CrowdStroke is demonstrating the significant risks of giving a third party remote root across your systems. I'd argue we don't have to accept this and can stop granting such vendors access to critical systems with acceptable security.

    Risks of AV/NGAV/EDR/XDR/whatever the next buzzword is don't just include functional bugs: false positives killing your critical processes, data exposure, or supply chain attacks via third party have all happened.

    The commonly repeated refrains of "bugs can happen to anyone" "this stuff is hard" etc. aren't reassuring or an acceptable answer when Delta, for example, has continued to mass-cancel flights for 4 days (so far!) Shrugging our collective shoulders and just hoping the AV - I mean EDR - vendors don't screw up again like they have several times before and continuing to install their agents everywhere is just not going to cut it.

    Nevertheless effective active endpoint security software is arguably necessary on endpoints where users surf the internet and open attachments to block malicious initial access, but on critical servers, the situation is reversed. If an agent for a common C2 framework is detected on a domain controller or OT control system, immediately killing it is likely not the best response option, even apart from the risks above. It is indicative of a far broader ongoing intrusion requiring a comprehensive incident response.

    But what is the alternative exactly? How else will you see that agent or credential dump or brute force attempt, etc.? Nearly all the high signal data from hashes of libraries loaded to process injection via CreateRemoteThread can be collected by built-in or configurable event collection with something like sysmon, forwarded to a SIEM, and analyzed against executable whitelists, YARA rules, VirusTotal, and more. Brute force attempts can be detected by these as well as by packet captures, request log analytics, etc.

    Nearly all the value of CrowdStrike comes not from the superiority of a few extra points their kernel driver can monitor, but from the analysts watching, investigating, tuning, and responding to the data collected. This is type of service that many managed security services can provide on a safer and more passive stack. Not only that, but you can often keep your data in your own SIEMs, in your network, in your datacenter, that you own.

    It can be the right choice for many systems. I'd argue it undoubtedly is for critical OT ICS systems, and likely is for many IT servers as well.

  10. [long post] #CrowdStroke is demonstrating the significant risks of giving a third party remote root across your systems. I'd argue we don't have to accept this and can stop granting such vendors access to critical systems with acceptable security.

    Risks of AV/NGAV/EDR/XDR/whatever the next buzzword is don't just include functional bugs: false positives killing your critical processes, data exposure, or supply chain attacks via third party have all happened.

    The commonly repeated refrains of "bugs can happen to anyone" "this stuff is hard" etc. aren't reassuring or an acceptable answer when Delta, for example, has continued to mass-cancel flights for 4 days (so far!) Shrugging our collective shoulders and just hoping the AV - I mean EDR - vendors don't screw up again like they have several times before and continuing to install their agents everywhere is just not going to cut it.

    Nevertheless effective active endpoint security software is arguably necessary on endpoints where users surf the internet and open attachments to block malicious initial access, but on critical servers, the situation is reversed. If an agent for a common C2 framework is detected on a domain controller or OT control system, immediately killing it is likely not the best response option, even apart from the risks above. It is indicative of a far broader ongoing intrusion requiring a comprehensive incident response.

    But what is the alternative exactly? How else will you see that agent or credential dump or brute force attempt, etc.? Nearly all the high signal data from hashes of libraries loaded to process injection via CreateRemoteThread can be collected by built-in or configurable event collection with something like sysmon, forwarded to a SIEM, and analyzed against executable whitelists, YARA rules, VirusTotal, and more. Brute force attempts can be detected by these as well as by packet captures, request log analytics, etc.

    Nearly all the value of CrowdStrike comes not from the superiority of a few extra points their kernel driver can monitor, but from the analysts watching, investigating, tuning, and responding to the data collected. This is type of service that many managed security services can provide on a safer and more passive stack. Not only that, but you can often keep your data in your own SIEMs, in your network, in your datacenter, that you own.

    It can be the right choice for many systems. I'd argue it undoubtedly is for critical OT ICS systems, and likely is for many IT servers as well.

  11. [long post] #CrowdStroke is demonstrating the significant risks of giving a third party remote root across your systems. I'd argue we don't have to accept this and can stop granting such vendors access to critical systems with acceptable security.

    Risks of AV/NGAV/EDR/XDR/whatever the next buzzword is don't just include functional bugs: false positives killing your critical processes, data exposure, or supply chain attacks via third party have all happened.

    The commonly repeated refrains of "bugs can happen to anyone" "this stuff is hard" etc. aren't reassuring or an acceptable answer when Delta, for example, has continued to mass-cancel flights for 4 days (so far!) Shrugging our collective shoulders and just hoping the AV - I mean EDR - vendors don't screw up again like they have several times before and continuing to install their agents everywhere is just not going to cut it.

    Nevertheless effective active endpoint security software is arguably necessary on endpoints where users surf the internet and open attachments to block malicious initial access, but on critical servers, the situation is reversed. If an agent for a common C2 framework is detected on a domain controller or OT control system, immediately killing it is likely not the best response option, even apart from the risks above. It is indicative of a far broader ongoing intrusion requiring a comprehensive incident response.

    But what is the alternative exactly? How else will you see that agent or credential dump or brute force attempt, etc.? Nearly all the high signal data from hashes of libraries loaded to process injection via CreateRemoteThread can be collected by built-in or configurable event collection with something like sysmon, forwarded to a SIEM, and analyzed against executable whitelists, YARA rules, VirusTotal, and more. Brute force attempts can be detected by these as well as by packet captures, request log analytics, etc.

    Nearly all the value of CrowdStrike comes not from the superiority of a few extra points their kernel driver can monitor, but from the analysts watching, investigating, tuning, and responding to the data collected. This is type of service that many managed security services can provide on a safer and more passive stack. Not only that, but you can often keep your data in your own SIEMs, in your network, in your datacenter, that you own.

    It can be the right choice for many systems. I'd argue it undoubtedly is for critical OT ICS systems, and likely is for many IT servers as well.

  12. [long post] #CrowdStroke is demonstrating the significant risks of giving a third party remote root across your systems. I'd argue we don't have to accept this and can stop granting such vendors access to critical systems with acceptable security.

    Risks of AV/NGAV/EDR/XDR/whatever the next buzzword is don't just include functional bugs: false positives killing your critical processes, data exposure, or supply chain attacks via third party have all happened.

    The commonly repeated refrains of "bugs can happen to anyone" "this stuff is hard" etc. aren't reassuring or an acceptable answer when Delta, for example, has continued to mass-cancel flights for 4 days (so far!) Shrugging our collective shoulders and just hoping the AV - I mean EDR - vendors don't screw up again like they have several times before and continuing to install their agents everywhere is just not going to cut it.

    Nevertheless effective active endpoint security software is arguably necessary on endpoints where users surf the internet and open attachments to block malicious initial access, but on critical servers, the situation is reversed. If an agent for a common C2 framework is detected on a domain controller or OT control system, immediately killing it is likely not the best response option, even apart from the risks above. It is indicative of a far broader ongoing intrusion requiring a comprehensive incident response.

    But what is the alternative exactly? How else will you see that agent or credential dump or brute force attempt, etc.? Nearly all the high signal data from hashes of libraries loaded to process injection via CreateRemoteThread can be collected by built-in or configurable event collection with something like sysmon, forwarded to a SIEM, and analyzed against executable whitelists, YARA rules, VirusTotal, and more. Brute force attempts can be detected by these as well as by packet captures, request log analytics, etc.

    Nearly all the value of CrowdStrike comes not from the superiority of a few extra points their kernel driver can monitor, but from the analysts watching, investigating, tuning, and responding to the data collected. This is type of service that many managed security services can provide on a safer and more passive stack. Not only that, but you can often keep your data in your own SIEMs, in your network, in your datacenter, that you own.

    It can be the right choice for many systems. I'd argue it undoubtedly is for critical OT ICS systems, and likely is for many IT servers as well.

  13. [long post] #CrowdStroke is demonstrating the significant risks of giving a third party remote root across your systems. I'd argue we don't have to accept this and can stop granting such vendors access to critical systems with acceptable security.

    Risks of AV/NGAV/EDR/XDR/whatever the next buzzword is don't just include functional bugs: false positives killing your critical processes, data exposure, or supply chain attacks via third party have all happened.

    The commonly repeated refrains of "bugs can happen to anyone" "this stuff is hard" etc. aren't reassuring or an acceptable answer when Delta, for example, has continued to mass-cancel flights for 4 days (so far!) Shrugging our collective shoulders and just hoping the AV - I mean EDR - vendors don't screw up again like they have several times before and continuing to install their agents everywhere is just not going to cut it.

    Nevertheless effective active endpoint security software is arguably necessary on endpoints where users surf the internet and open attachments to block malicious initial access, but on critical servers, the situation is reversed. If an agent for a common C2 framework is detected on a domain controller or OT control system, immediately killing it is likely not the best response option, even apart from the risks above. It is indicative of a far broader ongoing intrusion requiring a comprehensive incident response.

    But what is the alternative exactly? How else will you see that agent or credential dump or brute force attempt, etc.? Nearly all the high signal data from hashes of libraries loaded to process injection via CreateRemoteThread can be collected by built-in or configurable event collection with something like sysmon, forwarded to a SIEM, and analyzed against executable whitelists, YARA rules, VirusTotal, and more. Brute force attempts can be detected by these as well as by packet captures, request log analytics, etc.

    Nearly all the value of CrowdStrike comes not from the superiority of a few extra points their kernel driver can monitor, but from the analysts watching, investigating, tuning, and responding to the data collected. This is type of service that many managed security services can provide on a safer and more passive stack. Not only that, but you can often keep your data in your own SIEMs, in your network, in your datacenter, that you own.

    It can be the right choice for many systems. I'd argue it undoubtedly is for critical OT ICS systems, and likely is for many IT servers as well.

  14. So today I fly home via United. United is one of the airlines that is affected by #CrowdStroke. My flight is in 7 hours. I have carry on baggage only. I'm going to document my struggles so that y'all can enjoy my agony. I plan on turning this thread into a blogpost.

    "Enjoy"?

    I've tried to check in with the United website a few times yesterday and today. I get a few steps into the process and then the system says "no fuck you, check in at the airport". This morning I got as far as seat selection before the system errored out. I can't imagine what the airport is like now.

    I'm planning on getting to the airport very fucking early so that I can brave the line game that is undoubtedly full of other travellers that are also totally stuck and fucked over by this shitshow.

    If my flight is delayed, I doubt that United or Air Canada will comply with the Canadian flight delay compensation laws due to it being an IT issue. Probably should have bought insurance on the trip.

    Worst possible case, home is only a 9 hour drive away.

    I have status with Air Canada. One of the perks you get is the magic phone number that gets you to a human before the hold music loops. I called the magic phone number yesterday to see if there was any way to route around United's issues by flying with another airline.

    There is not. United is the only airline that flies into YOW from EWR. Worst case one of the itineraries I could go for is EWR -> YYZ -> YOW, or even EWR -> YUL -> YOW, but I see this as a last-ditch option. If things are super broken at the airport though, I may have to take that option.

  15. So today I fly home via United. United is one of the airlines that is affected by #CrowdStroke. My flight is in 7 hours. I have carry on baggage only. I'm going to document my struggles so that y'all can enjoy my agony. I plan on turning this thread into a blogpost.

    "Enjoy"?

    I've tried to check in with the United website a few times yesterday and today. I get a few steps into the process and then the system says "no fuck you, check in at the airport". This morning I got as far as seat selection before the system errored out. I can't imagine what the airport is like now.

    I'm planning on getting to the airport very fucking early so that I can brave the line game that is undoubtedly full of other travellers that are also totally stuck and fucked over by this shitshow.

    If my flight is delayed, I doubt that United or Air Canada will comply with the Canadian flight delay compensation laws due to it being an IT issue. Probably should have bought insurance on the trip.

    Worst possible case, home is only a 9 hour drive away.

    I have status with Air Canada. One of the perks you get is the magic phone number that gets you to a human before the hold music loops. I called the magic phone number yesterday to see if there was any way to route around United's issues by flying with another airline.

    There is not. United is the only airline that flies into YOW from EWR. Worst case one of the itineraries I could go for is EWR -> YYZ -> YOW, or even EWR -> YUL -> YOW, but I see this as a last-ditch option. If things are super broken at the airport though, I may have to take that option.

  16. So today I fly home via United. United is one of the airlines that is affected by #CrowdStroke. My flight is in 7 hours. I have carry on baggage only. I'm going to document my struggles so that y'all can enjoy my agony. I plan on turning this thread into a blogpost.

    "Enjoy"?

    I've tried to check in with the United website a few times yesterday and today. I get a few steps into the process and then the system says "no fuck you, check in at the airport". This morning I got as far as seat selection before the system errored out. I can't imagine what the airport is like now.

    I'm planning on getting to the airport very fucking early so that I can brave the line game that is undoubtedly full of other travellers that are also totally stuck and fucked over by this shitshow.

    If my flight is delayed, I doubt that United or Air Canada will comply with the Canadian flight delay compensation laws due to it being an IT issue. Probably should have bought insurance on the trip.

    Worst possible case, home is only a 9 hour drive away.

    I have status with Air Canada. One of the perks you get is the magic phone number that gets you to a human before the hold music loops. I called the magic phone number yesterday to see if there was any way to route around United's issues by flying with another airline.

    There is not. United is the only airline that flies into YOW from EWR. Worst case one of the itineraries I could go for is EWR -> YYZ -> YOW, or even EWR -> YUL -> YOW, but I see this as a last-ditch option. If things are super broken at the airport though, I may have to take that option.

  17. So today I fly home via United. United is one of the airlines that is affected by #CrowdStroke. My flight is in 7 hours. I have carry on baggage only. I'm going to document my struggles so that y'all can enjoy my agony. I plan on turning this thread into a blogpost.

    "Enjoy"?

    I've tried to check in with the United website a few times yesterday and today. I get a few steps into the process and then the system says "no fuck you, check in at the airport". This morning I got as far as seat selection before the system errored out. I can't imagine what the airport is like now.

    I'm planning on getting to the airport very fucking early so that I can brave the line game that is undoubtedly full of other travellers that are also totally stuck and fucked over by this shitshow.

    If my flight is delayed, I doubt that United or Air Canada will comply with the Canadian flight delay compensation laws due to it being an IT issue. Probably should have bought insurance on the trip.

    Worst possible case, home is only a 9 hour drive away.

    I have status with Air Canada. One of the perks you get is the magic phone number that gets you to a human before the hold music loops. I called the magic phone number yesterday to see if there was any way to route around United's issues by flying with another airline.

    There is not. United is the only airline that flies into YOW from EWR. Worst case one of the itineraries I could go for is EWR -> YYZ -> YOW, or even EWR -> YUL -> YOW, but I see this as a last-ditch option. If things are super broken at the airport though, I may have to take that option.

  18. So today I fly home via United. United is one of the airlines that is affected by #CrowdStroke. My flight is in 7 hours. I have carry on baggage only. I'm going to document my struggles so that y'all can enjoy my agony. I plan on turning this thread into a blogpost.

    "Enjoy"?

    I've tried to check in with the United website a few times yesterday and today. I get a few steps into the process and then the system says "no fuck you, check in at the airport". This morning I got as far as seat selection before the system errored out. I can't imagine what the airport is like now.

    I'm planning on getting to the airport very fucking early so that I can brave the line game that is undoubtedly full of other travellers that are also totally stuck and fucked over by this shitshow.

    If my flight is delayed, I doubt that United or Air Canada will comply with the Canadian flight delay compensation laws due to it being an IT issue. Probably should have bought insurance on the trip.

    Worst possible case, home is only a 9 hour drive away.

    I have status with Air Canada. One of the perks you get is the magic phone number that gets you to a human before the hold music loops. I called the magic phone number yesterday to see if there was any way to route around United's issues by flying with another airline.

    There is not. United is the only airline that flies into YOW from EWR. Worst case one of the itineraries I could go for is EWR -> YYZ -> YOW, or even EWR -> YUL -> YOW, but I see this as a last-ditch option. If things are super broken at the airport though, I may have to take that option.

  19. OHIRL: "I bet the person who would have known better got put on PIP and managed out as part of an AI pivot."

    I know, I know, I shouldn't laugh. I'm sorry.

    #CrowdStrike #CrowdStroke

  20. OHIRL: "I bet the person who would have known better got put on PIP and managed out as part of an AI pivot."

    I know, I know, I shouldn't laugh. I'm sorry.

    #CrowdStrike #CrowdStroke

  21. OHIRL: "I bet the person who would have known better got put on PIP and managed out as part of an AI pivot."

    I know, I know, I shouldn't laugh. I'm sorry.

  22. OHIRL: "I bet the person who would have known better got put on PIP and managed out as part of an AI pivot."

    I know, I know, I shouldn't laugh. I'm sorry.

    #CrowdStrike #CrowdStroke

  23. OHIRL: "I bet the person who would have known better got put on PIP and managed out as part of an AI pivot."

    I know, I know, I shouldn't laugh. I'm sorry.

    #CrowdStrike #CrowdStroke

  24. In the aftermath of the #ClownStrike ( #CrowdStroke or whatever) it would be interesting to watch the uptick in re-infection traffic in the coming days and weeks due to lost comms on the infected endpoints
    @greynoise should be well positioned to catch a bunch of replay scenarios

  25. In the aftermath of the #ClownStrike ( #CrowdStroke or whatever) it would be interesting to watch the uptick in re-infection traffic in the coming days and weeks due to lost comms on the infected endpoints
    @greynoise should be well positioned to catch a bunch of replay scenarios

  26. In the aftermath of the #ClownStrike ( #CrowdStroke or whatever) it would be interesting to watch the uptick in re-infection traffic in the coming days and weeks due to lost comms on the infected endpoints
    @greynoise should be well positioned to catch a bunch of replay scenarios

  27. Immerhin wissen wir jetzt, wer alles #crowdstike einsetzt. #crowdstroke 🤷🏼‍♀️

  28. Immerhin wissen wir jetzt, wer alles #crowdstike einsetzt. #crowdstroke 🤷🏼‍♀️

  29. Immerhin wissen wir jetzt, wer alles #crowdstike einsetzt. #crowdstroke 🤷🏼‍♀️

  30. Immerhin wissen wir jetzt, wer alles #crowdstike einsetzt. #crowdstroke 🤷🏼‍♀️

  31. Immerhin wissen wir jetzt, wer alles #crowdstike einsetzt. #crowdstroke 🤷🏼‍♀️

  32. This #crowdstrike issue is also a #microsoft issue. Even with far-reaching rights a third-party application should not be able to crash the whole system it is running on. #crowdstroke

  33. This #crowdstrike issue is also a #microsoft issue. Even with far-reaching rights a third-party application should not be able to crash the whole system it is running on. #crowdstroke

  34. This #crowdstrike issue is also a #microsoft issue. Even with far-reaching rights a third-party application should not be able to crash the whole system it is running on. #crowdstroke

  35. This #crowdstrike issue is also a #microsoft issue. Even with far-reaching rights a third-party application should not be able to crash the whole system it is running on. #crowdstroke

  36. The worst part about #Crowdstroke is realizing how many more or less critical systems are actually built on #Windows

  37. The worst part about #Crowdstroke is realizing how many more or less critical systems are actually built on #Windows

  38. The worst part about #Crowdstroke is realizing how many more or less critical systems are actually built on #Windows

  39. The worst part about #Crowdstroke is realizing how many more or less critical systems are actually built on #Windows

  40. The worst part about #Crowdstroke is realizing how many more or less critical systems are actually built on #Windows

  41. So what did we have in the past two weeks.

    Mozzila is now an ad company
    Proton drank the AI coolaid
    #crowdstroke #crowdstike #enshittification