this post was submitted on 19 Jul 2024
45 points (100.0% liked)
askchapo
22845 readers
332 users here now
Ask Hexbear is the place to ask and answer ~~thought-provoking~~ questions.
Rules:
-
Posts must ask a question.
-
If the question asked is serious, answer seriously.
-
Questions where you want to learn more about socialism are allowed, but questions in bad faith are not.
-
Try !feedback@hexbear.net if you're having questions about regarding moderation, site policy, the site itself, development, volunteering or the mod team.
founded 4 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I just thought of a metaphor for this stuff.
Imagine you have some secure compound, like a military base. It has good thick walls and fences all around, and also internally between areas, and there are checkpoints where guards check everyone's credentials, and only allow people into areas where they have any business being. This would be good security.
Unfortunately, Windows and lots of other software is not like that, since it was developed before the internet, when you actually needed physical access to mess with a computer. So most company's networks and computers are more like a university campus where people can just wander around as they please. So you could try to rebuild and retrofit everything to be more like the above mentioned military base, but that is hard, expensive and very disruptive.
So here comes Crowdstrike, with their sales pitch: We'll send a couple of security guards over, and they will look out for anyone suspicious and if they see something, they sound an alarm and maybe detain the person. Of course they need access to everything in order to do their job. You need to trust them to not fuck up and cause some damage or even to not hire infiltrators which would have full security clearance.
Well in this case, they got a faulty order from Crowdstrike to shut the whole thing down, not let anyone in, and no communication in and out. So now someone with some actual authority has to go down there, and tell them to stand down. And this happened probably to some double-digit percentage of bigger companies and institutions everywhere except in China, all at the same time.