The 2009 EU-Microsoft deal involved allowing software from others than Microsoft to replace Microsoft software on Windows. In the years before the deal, Microsoft had progressively added features to Windows that had previously been covered by software from other parties, forcing that software out of the market.
As in everything, do your research, read the terms and conditions before adopting new software. Particularly if your business depends on that software functioning correctly.

Microsoft updates have, before 2009 and after, caused Windows BSDs worldwide as well. The Crowdstrike-caused problems show moving outside the MS-universe does not protect you from BSDs.

My current employer uses a Crowdstrike alternative, not Windows Defender, and was not affected by the recent problems. Testing updates before implementing them is Standard Operating Procedure, even if exceptions are sometimes forced upon us.

When in danger or in doubt, blame EU when you find out.
 
Last edited:
I wonder if there is any vetting for the muppets that are allowed to upload this software onto Microsoft at kernel level. Seems like there should be. Maybe background wasn't an issue here, but it sure as hell could be in the future now that the weakness has been advertised.
 

 
 
From the Slashdot piece
Shareholders have sued CrowdStrike on Tuesday, claiming the cybersecurity company defrauded them by concealing how its inadequate software testing could cause the global software outage earlier this month that crashed millions of computers. Reuters reports: In a proposed class action filed on Tuesday night in the Austin, Texas federal court, shareholders said they learned that CrowdStrike's assurances about its technology were materially false and misleading when a flawed software update disrupted airlines, banks, hospitals and emergency lines around the world. They said CrowdStrike's share price fell 32% over the next 12 days, wiping out $25 billion of market value, as the outage's effects became known, Chief Executive George Kurtz was called to testify to the U.S. Congress, and Delta Air Lines reportedly hired prominent lawyer David Boies to seek damages.

The complaint cites statements including from a March 5 conference call where Kurtz characterized CrowdStrike's software as "validated, tested and certified." The lawsuit led by the Plymouth County Retirement Association of Plymouth, Massachusetts, seeks unspecified damages for holders of CrowdStrike Class A shares between Nov. 29, 2023 and July 29, 2024.
Suppose the court rules for the claimants in this case, then Crowdstrike will have to pay. This will negatively affect the financial situation of Crowdstrike. Which in turn will hurt Crowdstrike share prices.
I might have the wrong end of the stick here, but isn't taking financial risk essential to the way investing money in shares works to better increase capital, when compared to the return of a savings account?

The Crowdstrike blunder is not about providing false financial information to investors, but about a grave operational mistake. I believe the correct response from shareholders should be demanding a change of magement, not a financial claim.
 
Last edited:

Delta Airlines estimate it cost them $500 million.

Delta has yet to file a lawsuit against either CrowdStrike or Microsoft, but a person familiar with its actions confirmed to CNN on Tuesday that it had hired the law firm of high-profile attorney David Boies to pursue compensation from the two companies. Microsoft did not respond to a request for comment on Wednesday. A CrowdStrike spokesperson would only say, “We are aware of the reporting, but have no knowledge of a lawsuit and have no further comment.”

“We have no choice,” Bastian told CNBC. “We have to protect our shareholders, we have to protect our customers (and) our employees for the damage, not just the cost but the reputational damage.”
 
From the Slashdot piece

Suppose the court rules for the claimants in this case, then Crowdstrike will have to pay. This will negatively affect the financial situation of Crowdstrike. Which in turn will hurt Crowdstrike share prices.
I might have the wrong end of the stick here, but isn't taking financial risk essential to the way investing money in shares works to better increase capital, when compared to the return of a savings account?

The Crowdstrike blunder is not about providing false financial information to investors, but about a grave operational mistake. I believe the correct response from shareholders should be demanding a change of magement, not a financial claim.
This disaster has more than likely doomed the company in the long or even medium term. The shareholders doubtless have realised this, hence their attempt to begin recovering as much of their investment as possible while there is still time, as well as to strengthen their legal position in future bankruptcy and/or liquidation proceedings.
 
You shouldn’t be pushing out changes all at once like this to production. You usually have a small section of low impact canary clients where you test updates in case something goes wrong.The fact that they pushed kernel level changes without proper testing is pretty mind buggling.
 
You shouldn’t be pushing out changes all at once like this to production. You usually have a small section of low impact canary clients where you test updates in case something goes wrong.The fact that they pushed kernel level changes without proper testing is pretty mind buggling.
And customer-buggering.
 
The company routinely tests its software updates before pushing them out to customers, CrowdStrike said in the report. But on July 19, a bug in CrowdStrike’s cloud-based testing system — specifically, the part that runs validation checks on new updates prior to release — ended up allowing the software to be pushed out “despite containing problematic content data.”

The bad release was published just after midnight Eastern time on July 19, and rolled back an hour and a half later, at 1:27 a.m. Eastern, CrowdStrike said. But by then millions of computers had already automatically downloaded the faulty update. The issue affected only Windows devices, not Mac or Linux machines, and only those that were switched on and able to receive updates during those early morning hours.

Thanks to the timing of the incident, organizations in Europe and Asia “had more of their work day affected by the outage, unlike the Americas,” Fitch wrote in its blog post.

When Windows devices using CrowdStrike’s cybersecurity tools tried to access the flawed file, it caused an “out-of-bounds memory read” that “could not be gracefully handled, resulting in a Windows operating system crash,” CrowdStrike said.

Shaking my head in disbelief. I'm reminded of the Simpson gene. And Homer having an alert on his nuclear monitoring console - and pouring water on it for the short-circuits to "solve" the problem: by silencing the alarm once and for all. D'oh : problem solved. Let's have some donuts.
 



 
Last edited:
From the Business section [Markets] of THE TIMES (Irish edition, Saturday 24th August 2024)
Microsoft responds to outage with summit

Microsoft is to host a summit in September on improving cybersecurity systems, after a faulty update from Crowdstrike caused a global IT outage last month. The conference marks the first big step by Microsoft to address the issues that affected nearly 8.5 million Windows devices on July 19, disrupting operations across industries ranging from airlines to banks to healthcare. The event will be held on September at the company's headquarters in Redmond, Washington. "The Crowdstrike outage in July presents important lessons for us to apply as an ecosystem," Microsoft said. The outage raised concerns that many organisations are not well prepared to implement contingency plans when a single point of failure, such as an IT system, or a piece of software within it, goes down. "We look forward to bringing our perspective to the discussions on the need for a more resilient ecosystem," Crowdstrike said.
No, you are not imagining things, either the writer or editor left out the actual date the conference is supposed to be taking place on.
 
 

Please donate to support the forum.

Back
Top Bottom