@speedifylive: Replying to @Jh #greenscreen How did the Crowdstrike bug get through testing and how is the EU involved with the Microsoft outage? Here’s what we know so far #crowdstrike #microsoft #microsoftoutage #windows #technews #cybersecurity #technology
The kernel driver should’ve been tested in a development environment after it went through the initial compression and encryption in the pipeline
2024-07-24 01:19:37
716
Chris (Hyperidian) :
...is he calling it Cloud Strike? I swear he said cloud instead of crowd every time.
2024-07-24 13:27:22
15
Fkn_Cali🥑 :
So it’s the EUs fault crowdstrike didn’t do their proper testing and deployed on a Friday?
2024-07-24 07:02:36
0
The_RZH :
All OSes have facilities for kernel drivers. Cloudstrike has been causing kernel panics in Linux for a while.
2024-07-23 23:50:33
255
Speedify :
Should Apple have the same requirement from the EU? (they currently don’t)
2024-07-23 21:12:27
119
Rico 🌶️ :
Crowdstrike should have had thorough testing post release, canary deployment, and an automated roll back process.
2024-07-24 02:01:16
57
Jeydon Valtor :
Many video games alter the kernel for anti-cheat purposes. Lots of people would prefer not to give that level of access just to play a game, but it is becoming industry standard.
2024-07-24 14:51:54
55
Gillian ✨👁👄👁✨ :
crowdstrike is not brat
2024-07-23 21:24:52
51
L30 :
and what are Linux kernel modules? the only difference is that the Linux kernel is modular and you can fail them independently
2024-07-24 01:44:52
28
mintmage :
Great breakdown. Sounds like Crowdstrike is just poorly written
2024-07-24 12:04:30
22
Søuľ-ȚrøLL :
wow! you made tech talk interesting & enjoyable ... that is masterfull
2024-07-24 02:06:12
21
David Tiscareno :
As a QA expert, I seriously cannot believe that they did not run testing after the file compression. Any test analyst worth their salt would have set up a plan with the devs to test after that.
2024-07-25 14:42:35
17
Sea :
Why aren’t kernel level files required to have both checksums and signatures? 🤔
2024-07-24 02:35:41
16
Cerv :
The file should be signed and not easily copy/pasted to crash the computer, but dang :/
2024-07-23 21:17:58
15
ManAt5280 :
Why would they not push it to their own servers first, and then do 10% and finally push it to everyone??
2024-07-24 02:32:45
14
PavlovtheRussian :
Crowdstrike CEO was the CTO at McAfee when they took out Windows XP in a similar fashion
2024-07-24 00:39:57
13
d34nh4554n :
Why do people keep saying CLOUD strike???
2024-07-24 00:56:42
12
Phillip :
The thing that was left out was that cloudstrike did some heavy layoffs a little while back, and it's possible this is a result of reduced resources in change control.
2024-07-24 13:38:35
11
blk_diamond83 :
so they didn't really test it.
2024-07-24 10:46:19
8
Sleepwalker :
Why don’t Microsoft test the applications they allow on their OS though? Particularly if they’ve kernel access. Similar to what Apple do with the App Store. It’s not like they don’t have the money.
2024-07-26 07:32:10
6
Dane :
MacOS and Linux also allow Kernel extensions...
2024-07-24 05:33:45
6
miqueet :
The problem that people aren’t understanding is that with current CI/CD it’s really not possible to have a human test EVERY release at every step of their pipeline.
2024-07-24 02:08:58
4
winton :
did they really put the database in the kernel
2024-07-23 21:29:40
4
LetNoOneOutWorkYou :
The industry has been saying for years that allowing a government entity to control technology paths is the worst thing that can happen. This is a consumer driven issue.
2024-07-24 02:25:14
3
FlotillaWatch :
Blaming the EU is a cop out. Real question is why so many machines decided it was a good idea to use the same software instead of diversifying, which is precisely the EU's intent.
2024-07-25 17:19:52
2
ash_en_ley 🔻 :
so.. Microsoft tries to blame European fair competition laws against their monolopical practices for a 3rd party messing up, instead of the.. party that messed up xdddd
2024-07-24 15:50:17
2
seto17blue :
The International Criminal Courts made a ruling about Israel that day. And Crowdstrike has ties with Israel. This is probably all just a coincidence. @Positive Predictions made a video delving into it
2024-07-24 08:52:48
2
Gerard Sans :
Microsoft is looking for scapegoats and small print letters now. Regardless of who or how the issue was created. The distribution around the world unhinged is their doing.
2024-07-24 00:52:47
2
S :
Crowdstrike definition updates and sensor updates are separate, what he’s saying doesn’t make sense that wouldn’t be stored in kernel?? Also they can revert to earlier version once remediated
2024-07-23 22:22:15
2
Kirpaljeet :
Linux and Mac users be yawning away 😂
2024-07-29 10:58:48
1
Clint Vega :
If third-party apps have unrestricted access to the kernel, so do viruses and malwares
2024-07-27 20:17:04
1
mazzakre_90 :
It's current meta to fk around in the kernel it seems.. 😒
2024-07-26 20:17:09
1
Eric Wadsworth :
Server software is better on Linux. Windows is the wrong platform altogether.
2024-07-26 15:34:07
1
MB :
haha that's the most obvious blatant scapegoating who do they think they're fooling 😭
2024-07-26 09:08:40
1
Clark ༽ :
Why are they still using assembly of all things? Why not use a modern memory-safe language?
2024-07-25 20:10:32
1
instructions :
cloud srytike
2024-07-25 16:34:30
1
Tressa Stapley Wadsw :
@Eric Wadsworth fascinating
2024-07-25 11:45:50
1
...Erik_ :
I mean, as a former developer, testing on non development environment is important because the setup is different and it ensures the product is working
2024-07-24 12:57:00
1
piss_baby9000 :
Who is that guy? He’s interesting
2024-07-24 09:11:04
1
Günter :
on a Friday.. never
2024-07-24 08:24:17
1
nocti :
Crowdstrike is one thing, but why so many of their customers don't sandbox test patches before pushing them to production?
2024-07-24 05:20:20
1
leinohtee :
maybe they shouldn't have laid off their quality assurance team 🙃
2024-07-24 03:37:30
1
wut :
yeah reading conf files should be a userland thing. everything the guy said is right
2024-07-24 03:05:46
1
sofiaareinaa :
Underrated reporting
2024-07-24 02:39:45
1
Backseat Einstein :
what I saw was theirs also works like that but the actual driver didn't have good error handling so the driver crashes the kernel when it reads the def file
2024-07-24 02:23:21
1
RoboBellBivDevoe :
Worst bug I let out was software that unpurchased itself sometimes. My team found. The engineers said it wasn’t possible. The store cert team also hit it, but dismissed it as lower environment only
2024-07-24 01:58:59
1
bigboland41 :
I mean even on top of how they shouldn’t be doing that, it’s actually insane gross negligence to not input validate a pointer before dereferencing it
2024-07-23 22:04:24
1
Wry :
table
2024-07-23 21:32:23
1
To see more videos from user @speedifylive, please go to the Tikwm
homepage.