Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Filter this topic showing only the reply marked as answer View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9
RunningMan
9184 posts

Uber Geek
+1 received by user: 4834


  #3261712 20-Jul-2024 09:01
Send private message

Yep, just the normal ones though.




Rickles
3107 posts

Uber Geek
+1 received by user: 445

Trusted

  #3261713 20-Jul-2024 09:06
Send private message

Hmmm, local items must be on an infected machine/server and they haven't noticed? 😬


xpd

xpd
Geek of Coastguard
14115 posts

Uber Geek
+1 received by user: 4574

Retired Mod
ID Verified
Trusted
Lifetime subscriber

  #3261714 20-Jul-2024 09:14
Send private message

We dodged a bullet.....  had a couple of our systems BSOD but bought those up with no further issues. Think we ended up with 2 workstations that won't stop BSOD and thats it. 





XPD / Gavin

 

LinkTree

 

 

 




Rickles
3107 posts

Uber Geek
+1 received by user: 445

Trusted

  #3261749 20-Jul-2024 11:04
Send private message

Update:  If you are signed-in to a service such as Stuff, log out and normal viewing should be re-established.


Reanalyse
398 posts

Ultimate Geek
+1 received by user: 311


  #3261754 20-Jul-2024 11:29
Send private message

A few random comments on the outage - just my thoughts

 

1) Some off line websites (i.e Woolworths at the moment) have not even got any basic messages up to advise online customers.

 

2) The CEO of Cloudstrike used to be the CTO at McAfee

 

3) The more locked down end use PC's are, the slower the restoration (Woolworths still down, Foodstuffs got back very quickly)

 

4) Where staff are skilled and trusted, do not lock out the means by which they can recover using safe mode. Keep IS support local as far as possible.

 

   


Oblivian
7345 posts

Uber Geek
+1 received by user: 2117

ID Verified

  #3261755 20-Jul-2024 11:43
Send private message

Kiosks that get reimaged nearly daily are the reason you see the PoS/kiosks and supermarkets up so fast.

Edit core image, PXE them all again. Fixed.

The less locked down pcs, the more prone to targeting.

Crowdstrike is the one of the chosen providers to many government agencies around the world and those tied with them. Good luck convincing anyone those don't need bitlocker or open admin recovery.


 
 
 

Shop on-line at New World now for your groceries (affiliate link).
Batman
Mad Scientist
30012 posts

Uber Geek
+1 received by user: 6217

Trusted
Lifetime subscriber

  #3261756 20-Jul-2024 11:51
Send private message

msukiwi:

Reanalyse:.....I am relieved to see what services still work despite this massive issue.


Thankfully Geekzone is still up.



But how? Curious.

freitasm
BDFL - Memuneh
80646 posts

Uber Geek
+1 received by user: 41030

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3261758 20-Jul-2024 11:52
Send private message

Batman:

 

msukiwi:

 

Reanalyse:

 

.....I am relieved to see what services still work despite this massive issue.

 

Thankfully Geekzone is still up.

 



But how? Curious.

 

 

Not hard. By not running CrowdStrike.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


BarTender
3629 posts

Uber Geek
+1 received by user: 2572

ID Verified
Trusted
Lifetime subscriber

  #3261761 20-Jul-2024 12:08
Send private message

freitasm:

Batman: But how? Curious.



Not hard. By not running CrowdStrike.


I genuinely laughed out loud in the cafe I am sitting at while having a coffee and folks just looked at me like I was mad. 🧑‍🍳😘 @freitasm

networkn
Networkn
32862 posts

Uber Geek
+1 received by user: 15453

ID Verified
Trusted
Lifetime subscriber

  #3261766 20-Jul-2024 12:18
Send private message

Yes this is a Crowdstrike specific issue THIS time. 

 

Don't make the mistake of believing you not running crowdstrike, makes you entirely immune from such things. 

 

Vendors of all types push out updates all the time. This could happen with any vendor. MS have handed out updates many times which have broken functionality for millions of people. Defender is on millions and millions and millions of computers world wide. Defender had a major issue with an update it pushed out around 6 months ago that caused major issues. Not for everyone, and not to this level of outage, but it was wildly inconvenient. 


freitasm
BDFL - Memuneh
80646 posts

Uber Geek
+1 received by user: 41030

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3261793 20-Jul-2024 12:39
Send private message

networkn:

 

Yes this is a Crowdstrike specific issue THIS time. 

 

Don't make the mistake of believing you not running crowdstrike, makes you entirely immune from such things. 

 

 

Of course not. This happened before, with McAfee and ESET. 

 

It will happen again. It's just that the scale now and reliance on interconnected systems is much larger than 15 years ago.

 

The question seemed to be specific to this issue, not in general.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


 
 
 
 

Shop now for Lego sets and other gifts (affiliate link).
Rikkitic
Awrrr
19062 posts

Uber Geek
+1 received by user: 16302

Lifetime subscriber

  #3261812 20-Jul-2024 13:27
Send private message

networkn:

 

Yes this is a Crowdstrike specific issue THIS time. 

 

Don't make the mistake of believing you not running crowdstrike, makes you entirely immune from such things. 

 

Vendors of all types push out updates all the time. This could happen with any vendor. MS have handed out updates many times which have broken functionality for millions of people. Defender is on millions and millions and millions of computers world wide. Defender had a major issue with an update it pushed out around 6 months ago that caused major issues. Not for everyone, and not to this level of outage, but it was wildly inconvenient. 

 

 

This is exactly the reason I avoid automatic updates and only very selectively allow minimal others after waiting a decent time to make sure they aren't going to kill something important. So far it has worked for me. 

 

 

 

 





Plesse igmore amd axxept applogies in adbance fir anu typos

 


 


lxsw20
3689 posts

Uber Geek
+1 received by user: 2174

Subscriber

  #3261815 20-Jul-2024 13:38
Send private message

Reanalyse:

 

Foodstuffs got back very quickly

 

 

 

 

 

I would guess that's because they also don't use Crowdstrike?


lxsw20
3689 posts

Uber Geek
+1 received by user: 2174

Subscriber

  #3261816 20-Jul-2024 13:39
Send private message

Rikkitic:

 

This is exactly the reason I avoid automatic updates and only very selectively allow minimal others after waiting a decent time to make sure they aren't going to kill something important. So far it has worked for me. 

 

 

 

 

This wouldn't have saved you in the slightest in this situation. 


BarTender
3629 posts

Uber Geek
+1 received by user: 2572

ID Verified
Trusted
Lifetime subscriber

  #3261818 20-Jul-2024 13:49
Send private message

I do firmly blame much of the situation on Microsoft being unable to supply an OS with sufficient hardening steps that a separate vendor is required for EDR rather than the OS being sufficient.
I also blame IT Security management requirements in some industries such as Telco, Fintech, Medical and Aviation that rightfully have vulnerability policies that if a zero day drops it needs to be patched immediately before you get pwned and having mitigation tools to reduce your risk surface on the unknown unknowns. All I need to say is “log4j, OpenSSL shell shock and xz” where similar issues that impact Linux hosts.

The main difference is where complexity and the environment grows and managers don’t want to pay staff to be available 24/7 for remediation that tools will come in place to replace humans with automation… and when those tools are deployed at scale this could very easily have happened on any platform.

Until there is a point where human intervention is considered an asset not a liability in critical technical infrastructure services I can see this happening again. Perhaps not on this scale… but I can see how it could easily happen again even without the possibility of a supply chain attack.

1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9
Filter this topic showing only the reply marked as answer View this topic in a long page with up to 500 replies per page Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.