Aftermath of CrowdStrike IT Outage…What Happens Now??

preview_player
Показать описание
🔴🔴MASSIVE SALE on ALL Tech Courses🔴🔴

Did you know that CrowdStrike Brought Down 8.5 Million Computers? Let’s discuss the aftermath of the CrowdStrike global IT outage and the response that you should take. What actually happened, what are the learnings and what should you now do as an IT professional? We’ll discuss
- What happened
- Should I Ditch CrowdStrike Now?
- How has CrowdStrikes Responded?
- Should I use Mac or Linux instead?
- and much more

———TIMESTAMPS——
0:55 IT Tech Responses
2:34 What Did CrowdStrike Do?
3:08 Should I Ditch CrowdStrike Now?
4:23 How I Screwed Up
6:48 CrowdStrikes Response
8:29 Should I use Mac or Linux instead?
9:28 We’ve Got a Bigger Problem!
11:00 Redundant Systems?
11:24 What Keeps Me Up at Night

See my quick fix video here -

STUFF I RECOMMEND

——————————————————

My popular courses -

——————————————————

MY GEAR (some of it…)

——————————————————

ABOUT ME:
My name is Emilio Aguero and I’m a technology enthusiast from Melbourne Australia. I’ve been into computers ever since setting up my first pentium computer years ago. I love technology and make videos about all things tech every week. Would love it if you support my channel by subscribing and staying up to date with what I'm releasing!

⮕⮕ New Videos Sundays 2pm GMT ⬅⬅

——————————————————

GET IN TOUCH:

————————————————————————————————————————————————————————————
Рекомендации по теме
Комментарии
Автор

The CEO of CrowdStrike, George Kurtz used to be the Chief Technology Officer of McAfee in 2010, when a security update from the antivirus firm crashed tens of thousands of computers.

ying-ymut
Автор

The crash happened because CrowdStrike Falcon executed in ring 0 (kernel mode). I understand that this is necessary in order to provide system-wide anti-malware services. And if that was not bad enough it also registered itself as a boot-start driver, which means that Windows will not boot without Falcon. This presents two major opportunies for improvements:
1) minimize the amount of logic that absolutely needs to run in ring 0 and move the rest to ring 1 (user mode)
2) rethink registering Falcon as boot-start driver
In addition, updates should be staged. There is no need for the entire world to get the updates all at once.

In the meantime, I hope that Microsoft reverts the CrowdStrike WHQL certification until considerable improvements are made.

bendono
Автор

the problem is the update went directly into production systems, instead of test systems first. especially for airports... major mistake. rather than switch vendors, learn to stagger updates. I worked for a large insurance company. new windows patches were tested in development first for a week, and then into production once we detected no issues.

enigmawpg
Автор

It feels like if you want to stay with crowd strike that you can probably re-negotiate the cost of your contract, but I doubt many higher up executives will want to

MStrong
Автор

Obviously CrowdStrike should have done several things differently, given their root system access on such a global scale, and the fact that these systems even work this way at all is a questionable thing to have going on anyway. For the customers however, this incident is superficially indistinguishable from a cyberattack, and for those who find recovery in this case to be problematic, what does that reveal about their preparedness for the real thing? The real takeaway is a call for businesses to make sure their continuity plans are up to the task.

richardbrekke
Автор

We can't avoid this but none of security crap should be in kernel driver, ever. Clownstrike should be held responsible for damages. That's how you minimize chances of such occurrences in the future.

hensonk
Автор

It didn't go out "without adequate testing":
It went out WITH NO TESTING WHATSOEVER ON ANY WINDOWS MACHINE (maybe they tested on XP and windows 7 w/o sp1 since those weren't affected)
There's a big difference between nuking a specific generation 10 intel cpu or a specific model of hp/dell vs what CS did.
Also, never push updates to prod on friday, especially untested ones.

calmyflory
Автор

one thing that could have prevented this at scale is some kind of regulation enforcing vender diversity, its rediculous that all this key infrastructure is vulnerable because of ONE COMPETITION.

RoninLeonim
Автор

TBH, people still gone use windows and them so it’s not alternative’s but lessons learned.

WatsonInfosec
Автор

Crowdstrike is no longer the best. It's now the worst choice. The damage done is the same as a zeroday hack. Regardless of intent, the result is the same. Judge by their actions not by their word. This is just like sony's rootkit. lol

draconpern
Автор

Crowdstrike work with the WEF. That alone makes this whole situation sus AF

justanoob
Автор

Dude Microsoft's f*** s*** up all the time!

andrewz