CrowdStrike effectively bricked windows, Mac and Linux today.

Windows machines won’t boot, and Mac and Linux work is abandoned because all their users are on twitter making memes.

Incredible work.

you are viewing a single comment's thread
view the rest of the comments
[–] 113 points 2 years ago (25 children)

Imagine this happening during open heart surgery and all the monitors go blue!

  • source
  • hideshow 25 child comments
  • [+] 131 points 2 years ago (13 children)
  • [–] 120 points 2 years ago (8 children)

    Fear not, that's why we deploy extra security software to these critical systems. It's called Crowdsource or something.

  • source
  • parent
  • hideshow 8 child comments
  • [–] 47 points 2 years ago (6 children)
  • [–] 32 points 2 years ago (3 children)
  • [–] 13 points 2 years ago* (last edited 2 years ago)

    Critical surgery computers may also be running under Windows LTSC, so they might not get the CrowdStrike patch. Maybe...

    Edit: So the issue is apparently caused by CrowdStrike. So, unless the surgery computers also use CrowdStrike then it would be fine. Unless, of course, if they use CrowdStrike on surgery computers...

  • source
  • parent
  • [–] 7 points 2 years ago

    I'd heard some hospitals were affected. They cancelled appointments and non-critical surgeries.

    I'm guessing it was mostly their "behind the desk" computers that got affected, not the computers used to control the important stuff. The computers in patients' rooms may have been affected as well, but (at least in the US) those are usually just used to record information about medicine given and other details about the patient, nothing critical that can't be done manually.

  • source
  • parent
  • [–] 26 points 2 years ago (5 children)

    Anecdotal, but my spouse was in surgery during the outage and it went fine, so I imagine they take precautions (like probably having a test machine for updates before they install anything on the real one, maybe)

  • source
  • parent
  • hideshow 5 child comments
  • [–] 37 points 2 years ago

    There were no test rings for this one and it wasn't a user controlled update. It was pushed by CS in a way that couldn't be intercepted/tested/vetted by the consumer unless your device either doesn't have CS installed or isn't on an external network.. or I suppose you could block CS connections at the firewall. πŸ€·β€β™‚οΈ

  • source
  • parent
  • [–] 10 points 2 years ago (1 child)

    Good News! Unless something has changed since I worked in healthcare IT, those systems are far too old to be impacted!

    I'm half-joking. I don't know what that kind of equipment runs, but I would guess something embedded. The nuke-med stuff was mostly linux and various lab analyzers were also something embedded though they interface with all sorts of things (which can very well be windows). Pharmaceutical dispensers ran various linux-like OS's (though I couldn't even tell you the names anymore). Some medical records stuff was also proprietary, but Windows was replacing most of it near the end of my time.

    One place we had ran their keycard system all on a windows 3.1 box still. I don't doubt some modern systems also are running on Windows which has interesting implications for getting into/out of places.

    That said, a lot of that stuff doesn't touch the outside internet at all unless someone has done something horribly wrong. Medical records systems often do, though (including for billing and insurance stuff).

  • source
  • parent
  • hideshow 1 child comment
  • [–] [S] 1 point 2 years ago

    I was just watching this show called Connections and the first episode was about a power blackout and it showed how the lights went out during a birth.

    Great show it went on about what do you do if the power stays off permanently and how we aren't well prepared for that and how to start a civilization after you kill some farmers and steal their land but non of their tools work without power either and if you know how to mount an old-school plow to oxen

  • source
  • parent