▲ 65 ▼ Are We Too Dependent on Microsoft? (www.youtube.com) submitted 2 years ago by Beaver@lemmy.ca to c/canada@lemmy.ca 19 comments fedilink hide all child comments
[+] TheBat@lemmy.world 2 points 2 years ago* (last edited 6 months ago) (3 children) [deleted] permalink fedilink source parent hideshow 6 child comments replies: [–] lemmyng@lemmy.ca 3 points 2 years ago (1 child) It has a little bit to do with the OS. Windows does not have the same sandboxing capability for modules that Linux provides. The fact that the sensor needs to run in ring 0 is a problem, and eBPF at least mitigates much of the issue in Linux. But I think you meant that CrowdStrike is by no means blameless, and I agree - they have a long history of shitty implementations, and rightly deserve to be the focus of our anger. permalink fedilink source parent hideshow 2 child comments replies: [+] TheBat@lemmy.world 1 point 2 years ago* (last edited 6 months ago) (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] lemmyng@lemmy.ca 1 point 2 years ago IIRC those were the non-eBPF versions of the sensor. permalink fedilink source parent [–] cyberpunk007@lemmy.ca 1 point 2 years ago I know it has nothing to do with macos. I agree it's the QA piece. I heard upper managements theme was "two feet on the gas". Also the CEO was the CTO of McAfee when they had a similar issue back in 2010 if I'm not mistaken. 🙃 permalink fedilink source parent [–] nyan@lemmy.cafe 1 point 2 years ago Hopefully there are a bunch of programmers there right now standing in a circle around the desk of some manager and bombarding them with a continuous chant of "We told you so!" We knew in the 1990s not to trust stuff coming in off the Internet to be what it claims or reach its destination unmangled, and as I understand it, the software was blindly attempting to parse unverified threat definition files it had downloaded. Doing it all in ring 0 was just that extra crowning touch. This should have been caught before it even got to QA. permalink fedilink source parent
[–] lemmyng@lemmy.ca 3 points 2 years ago (1 child) It has a little bit to do with the OS. Windows does not have the same sandboxing capability for modules that Linux provides. The fact that the sensor needs to run in ring 0 is a problem, and eBPF at least mitigates much of the issue in Linux. But I think you meant that CrowdStrike is by no means blameless, and I agree - they have a long history of shitty implementations, and rightly deserve to be the focus of our anger. permalink fedilink source parent hideshow 2 child comments replies: [+] TheBat@lemmy.world 1 point 2 years ago* (last edited 6 months ago) (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] lemmyng@lemmy.ca 1 point 2 years ago IIRC those were the non-eBPF versions of the sensor. permalink fedilink source parent
[+] TheBat@lemmy.world 1 point 2 years ago* (last edited 6 months ago) (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] lemmyng@lemmy.ca 1 point 2 years ago IIRC those were the non-eBPF versions of the sensor. permalink fedilink source parent
[–] lemmyng@lemmy.ca 1 point 2 years ago IIRC those were the non-eBPF versions of the sensor. permalink fedilink source parent
[–] cyberpunk007@lemmy.ca 1 point 2 years ago I know it has nothing to do with macos. I agree it's the QA piece. I heard upper managements theme was "two feet on the gas". Also the CEO was the CTO of McAfee when they had a similar issue back in 2010 if I'm not mistaken. 🙃 permalink fedilink source parent
[–] nyan@lemmy.cafe 1 point 2 years ago Hopefully there are a bunch of programmers there right now standing in a circle around the desk of some manager and bombarding them with a continuous chant of "We told you so!" We knew in the 1990s not to trust stuff coming in off the Internet to be what it claims or reach its destination unmangled, and as I understand it, the software was blindly attempting to parse unverified threat definition files it had downloaded. Doing it all in ring 0 was just that extra crowning touch. This should have been caught before it even got to QA. permalink fedilink source parent