@speedifylive: Replying to @Jh #greenscreen How did the Crowdstrike bug get through testing and how is the EU involved with the Microsoft outage? Here’s what we know so far #crowdstrike #microsoft #microsoftoutage #windows #technews #cybersecurity #technology

Speedify
Speedify
Open In TikTok:
Region: US
Tuesday 23 July 2024 21:10:48 GMT
310274
13596
441
1525

Music

Download

Comments

natesofamerica
Nate 🔻 :
The kernel driver should’ve been tested in a development environment after it went through the initial compression and encryption in the pipeline
2024-07-24 01:19:37
716
hyperidian
Chris (Hyperidian) :
...is he calling it Cloud Strike? I swear he said cloud instead of crowd every time.
2024-07-24 13:27:22
15
caliwholesome
Fkn_Cali🥑 :
So it’s the EUs fault crowdstrike didn’t do their proper testing and deployed on a Friday?
2024-07-24 07:02:36
0
the_rzh
The_RZH :
All OSes have facilities for kernel drivers. Cloudstrike has been causing kernel panics in Linux for a while.
2024-07-23 23:50:33
255
speedifylive
Speedify :
Should Apple have the same requirement from the EU? (they currently don’t)
2024-07-23 21:12:27
119
ricardogomez00001
Rico 🌶️ :
Crowdstrike should have had thorough testing post release, canary deployment, and an automated roll back process.
2024-07-24 02:01:16
57
silkcrown
Jeydon Valtor :
Many video games alter the kernel for anti-cheat purposes. Lots of people would prefer not to give that level of access just to play a game, but it is becoming industry standard.
2024-07-24 14:51:54
55
gillian_paints
Gillian ✨👁👄👁✨ :
crowdstrike is not brat
2024-07-23 21:24:52
51
bitsandburnouts
L30 :
and what are Linux kernel modules? the only difference is that the Linux kernel is modular and you can fail them independently
2024-07-24 01:44:52
28
mintmage
mintmage :
Great breakdown. Sounds like Crowdstrike is just poorly written
2024-07-24 12:04:30
22
s0ul_tr0ll
Søuľ-ȚrøLL :
wow! you made tech talk interesting & enjoyable ... that is masterfull
2024-07-24 02:06:12
21
kcclubkirby
David Tiscareno :
As a QA expert, I seriously cannot believe that they did not run testing after the file compression. Any test analyst worth their salt would have set up a plan with the devs to test after that.
2024-07-25 14:42:35
17
breezemakesmesneeze
Sea :
Why aren’t kernel level files required to have both checksums and signatures? 🤔
2024-07-24 02:35:41
16
cerv.antes
Cerv :
The file should be signed and not easily copy/pasted to crash the computer, but dang :/
2024-07-23 21:17:58
15
manat5280
ManAt5280 :
Why would they not push it to their own servers first, and then do 10% and finally push it to everyone??
2024-07-24 02:32:45
14
pavlovtherussian
PavlovtheRussian :
Crowdstrike CEO was the CTO at McAfee when they took out Windows XP in a similar fashion
2024-07-24 00:39:57
13
d34nh4554n
d34nh4554n :
Why do people keep saying CLOUD strike???
2024-07-24 00:56:42
12
pln08088
Phillip :
The thing that was left out was that cloudstrike did some heavy layoffs a little while back, and it's possible this is a result of reduced resources in change control.
2024-07-24 13:38:35
11
blk_diamond83
blk_diamond83 :
so they didn't really test it.
2024-07-24 10:46:19
8
sleepwalking925
Sleepwalker :
Why don’t Microsoft test the applications they allow on their OS though? Particularly if they’ve kernel access. Similar to what Apple do with the App Store. It’s not like they don’t have the money.
2024-07-26 07:32:10
6
thegreat4289
Dane :
MacOS and Linux also allow Kernel extensions...
2024-07-24 05:33:45
6
themiqueet
miqueet :
The problem that people aren’t understanding is that with current CI/CD it’s really not possible to have a human test EVERY release at every step of their pipeline.
2024-07-24 02:08:58
4
curtain.boy
winton :
did they really put the database in the kernel
2024-07-23 21:29:40
4
entupernural
LetNoOneOutWorkYou :
The industry has been saying for years that allowing a government entity to control technology paths is the worst thing that can happen. This is a consumer driven issue.
2024-07-24 02:25:14
3
flotillawatch
FlotillaWatch :
Blaming the EU is a cop out. Real question is why so many machines decided it was a good idea to use the same software instead of diversifying, which is precisely the EU's intent.
2024-07-25 17:19:52
2
ash.en.ley
ash_en_ley 🔻 :
so.. Microsoft tries to blame European fair competition laws against their monolopical practices for a 3rd party messing up, instead of the.. party that messed up xdddd
2024-07-24 15:50:17
2
seto17blue
seto17blue :
The International Criminal Courts made a ruling about Israel that day. And Crowdstrike has ties with Israel. This is probably all just a coincidence. @Positive Predictions made a video delving into it
2024-07-24 08:52:48
2
gerardsans5
Gerard Sans :
Microsoft is looking for scapegoats and small print letters now. Regardless of who or how the issue was created. The distribution around the world unhinged is their doing.
2024-07-24 00:52:47
2
swankypanky07
S :
Crowdstrike definition updates and sensor updates are separate, what he’s saying doesn’t make sense that wouldn’t be stored in kernel?? Also they can revert to earlier version once remediated
2024-07-23 22:22:15
2
italianstallion975
Kirpaljeet :
Linux and Mac users be yawning away 😂
2024-07-29 10:58:48
1
clint_vega
Clint Vega :
If third-party apps have unrestricted access to the kernel, so do viruses and malwares
2024-07-27 20:17:04
1
mazzakre_90
mazzakre_90 :
It's current meta to fk around in the kernel it seems.. 😒
2024-07-26 20:17:09
1
wad4ever
Eric Wadsworth :
Server software is better on Linux. Windows is the wrong platform altogether.
2024-07-26 15:34:07
1
mb503
MB :
haha that's the most obvious blatant scapegoating who do they think they're fooling 😭
2024-07-26 09:08:40
1
wow_its_clark
Clark ༽ :
Why are they still using assembly of all things? Why not use a modern memory-safe language?
2024-07-25 20:10:32
1
instructions09
instructions :
cloud srytike
2024-07-25 16:34:30
1
tressawad
Tressa Stapley Wadsw :
@Eric Wadsworth fascinating
2024-07-25 11:45:50
1
..erik_
...Erik_ :
I mean, as a former developer, testing on non development environment is important because the setup is different and it ensures the product is working
2024-07-24 12:57:00
1
piss_baby9000
piss_baby9000 :
Who is that guy? He’s interesting
2024-07-24 09:11:04
1
gsm156
Günter :
on a Friday.. never
2024-07-24 08:24:17
1
nocti07
nocti :
Crowdstrike is one thing, but why so many of their customers don't sandbox test patches before pushing them to production?
2024-07-24 05:20:20
1
leinehter
leinohtee :
maybe they shouldn't have laid off their quality assurance team 🙃
2024-07-24 03:37:30
1
checksumerror
wut :
yeah reading conf files should be a userland thing. everything the guy said is right
2024-07-24 03:05:46
1
sofiaareinaa
sofiaareinaa :
Underrated reporting
2024-07-24 02:39:45
1
backseateinstein
Backseat Einstein :
what I saw was theirs also works like that but the actual driver didn't have good error handling so the driver crashes the kernel when it reads the def file
2024-07-24 02:23:21
1
robobellbivdevoe
RoboBellBivDevoe :
Worst bug I let out was software that unpurchased itself sometimes. My team found. The engineers said it wasn’t possible. The store cert team also hit it, but dismissed it as lower environment only
2024-07-24 01:58:59
1
bigboland41
bigboland41 :
I mean even on top of how they shouldn’t be doing that, it’s actually insane gross negligence to not input validate a pointer before dereferencing it
2024-07-23 22:04:24
1
.wry_
Wry :
table
2024-07-23 21:32:23
1
To see more videos from user @speedifylive, please go to the Tikwm homepage.

Other Videos


About