{"id":44179,"date":"2024-07-22T14:16:02","date_gmt":"2024-07-22T18:16:02","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=44179"},"modified":"2024-09-17T09:55:17","modified_gmt":"2024-09-17T13:55:17","slug":"crowdstrike-update-causes-bsod","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2024\/07\/22\/crowdstrike-update-causes-bsod\/","title":{"rendered":"CrowdStrike Update Causes BSOD"},"content":{"rendered":"<p><a href=\"https:\/\/www.dailymail.co.uk\/news\/article-13651137\/The-outage-world-seen-Microsoft-breakdown-sparks-chaos-planes-trains-grounded-GPs-NHS-mayhem-shops-closed-Premier-League-tickets-cancelled-banks-TV-channels-knocked-offline-massive-global-crisis.html\">Rory Tingle et al.<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.dailymail.co.uk\/news\/article-13651137\/The-outage-world-seen-Microsoft-breakdown-sparks-chaos-planes-trains-grounded-GPs-NHS-mayhem-shops-closed-Premier-League-tickets-cancelled-banks-TV-channels-knocked-offline-massive-global-crisis.html\"><p>The &lsquo;most serious IT outage the world has ever seen&rsquo; sparked global chaos today - with planes and trains halted, the <a href=\"https:\/\/www.dailymail.co.uk\/news\/nhs\/index.html\">NHS<\/a> disrupted, shops <a href=\"https:\/\/www.dailymail.co.uk\/news\/article-13650659\/Microsoft-LIVE-Outage-sparks-chaos-globe-TV-channels-airports-banks-knocked-offline.html\">closed, football teams unable to sell tickets and banks and TV channels knocked offline<\/a>.<\/p><\/blockquote>\n\n<p>See also: <a href=\"https:\/\/old.reddit.com\/r\/crowdstrike\/comments\/1e6vmkf\/bsod_error_in_latest_crowdstrike_update\/\">Reddit<\/a>, <a href=\"https:\/\/news.ycombinator.com\/item?id=41002195\">Hacker News<\/a>, and <a href=\"https:\/\/tech.slashdot.org\/story\/24\/07\/21\/214222\/third-day-of-1000-cancelled-flights-just-in-the-us-after-crowdstrike-outage\">Slashdot<\/a>.<\/p>\n\n<p><a href=\"https:\/\/www.nytimes.com\/2024\/07\/18\/us\/frontier-flights-grounded-microsoft.html\">Qasim Nauman<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=41001959\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.nytimes.com\/2024\/07\/18\/us\/frontier-flights-grounded-microsoft.html\">\n<p>Frontier Airlines briefly grounded all flights on Thursday amid a major outage in Microsoft networks, which also knocked out some computer systems at low-cost carriers Allegiant Air and Sun Country Airlines.<\/p>\n<p>Microsoft said on the status page for Azure, its flagship cloud computing platform, that the problem began at 5:56 p.m. and affected multiple systems for customers in the central United States.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/arstechnica.com\/information-technology\/2024\/07\/crowdstrike-fixes-start-at-reboot-up-to-15-times-and-get-more-complex-from-there\/\">Andrew Cunningham<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=41007898\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/arstechnica.com\/information-technology\/2024\/07\/crowdstrike-fixes-start-at-reboot-up-to-15-times-and-get-more-complex-from-there\/\">\n<p>Airlines, payment processors, 911 call centers, TV networks, and other businesses have been scrambling this morning after a buggy update to CrowdStrike's Falcon security software caused Windows-based systems to crash with a dreaded blue screen of death (BSOD) error message.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/major-microsoft-365-outage-caused-by-azure-configuration-change\/\">Sergiu Gatlan<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=41005056\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/major-microsoft-365-outage-caused-by-azure-configuration-change\/\">\n<p>The list of services impacted by the outage includes Microsoft Defender, Intune, Teams, PowerBI, Fabric, OneNote, OneDrive for Business, SharePoint Online, Windows 365, Viva Engage, Microsoft Purview, and the Microsoft 365 admin center.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/www.wheresyoured.at\/crowdstruck-2\/\">Edward Zitron<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.wheresyoured.at\/crowdstruck-2\/\"><p>What&rsquo;s happened today with Crowdstrike is completely unprecedented (and I&rsquo;ll get to why shortly), and on the scale of the much-feared Y2K bug that threatened to ground the entirety of the world&rsquo;s computer-based infrastructure once the Year 2000 began.<\/p><p>[&#8230;]<\/p><p>The problem here is systemic &mdash; that there is a company that the majority of people affected by this outage had no idea existed until today that Microsoft trusted to the extent that they were able to push an update that broke the back of a huge chunk of the world&rsquo;s digital infrastructure.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/www.tomshardware.com\/software\/windows\/windows-31-saves-the-day-during-crowdstrike-outage\">Jowi Morales<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.tomshardware.com\/software\/windows\/windows-31-saves-the-day-during-crowdstrike-outage\">\n<p>Southwest Airlines, the fourth largest airline in the US, is seemingly unaffected by the problematic CrowdStrike update that caused millions of computers to BSoD (Blue Screen of Death) because it used Windows 3.1.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/www.macrumors.com\/2024\/07\/19\/global-it-outage-limited-to-windows-pcs\/\">Tim Hardwick<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.macrumors.com\/2024\/07\/19\/global-it-outage-limited-to-windows-pcs\/\">\n<p>The cause of the failure has been identified as an update to Crowdstrike Falcon antivirus software installed on Windows 10 PCs, but Mac and Linux machines running the same cybersecurity software have been spared.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/www.theregister.com\/2024\/07\/21\/crowdstrike_linux_crashes_restoration_tools\/\">Simon Sharwood<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.theregister.com\/2024\/07\/21\/crowdstrike_linux_crashes_restoration_tools\/\"><p>CrowdStrike&rsquo;s now-infamous Falcon Sensor software, which last week led to widespread outages of Windows-powered computers, has also caused crashes of Linux machines.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/www.theverge.com\/2024\/7\/19\/24201717\/windows-bsod-crowdstrike-outage-issue\">Tom Warren<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.theverge.com\/2024\/7\/19\/24201717\/windows-bsod-crowdstrike-outage-issue\">\n<p>CrowdStrike says the issue has been identified and a fix has been deployed, but fixing these machines won&rsquo;t be simple for IT admins. The root cause appears to be an update to the kernel-level driver that CrowdStrike uses to secure Windows machines. While CrowdStrike <a href=\"https:\/\/supportportal.crowdstrike.com\/s\/login\/?ec=302&amp;startURL=%2Fs%2Farticle%2FTech-Alert-Windows-crashes-related-to-Falcon-Sensor-2024-07-19\">identified the issue<\/a> and reverted the faulty update after &ldquo;widespread reports of BSODs on Windows hosts,&rdquo; it doesn&rsquo;t appear to help machines that have already been impacted.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/taoofmac.com\/space\/links\/2024\/07\/19\/1130\">Rui Carmo<\/a>:<\/p>\n<blockquote cite=\"https:\/\/taoofmac.com\/space\/links\/2024\/07\/19\/1130\">\n<p>This is why I keep telling people that third-party kernel extensions should be banned from production servers, period.<\/p>\n<p>And shipping LIVE cloud updates direct to endpoints, unchecked, without any canaries?<\/p>\n<p>[&#8230;]<\/p>\n<p>But since most of the affected systems are in a boot loop that may well require physical (or IPMI) access to the machine.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/eclecticlight.co\/2024\/07\/22\/could-our-macs-be-crowdstruck\/\">Howard Oakley<\/a>:<\/p>\n<blockquote cite=\"https:\/\/eclecticlight.co\/2024\/07\/22\/could-our-macs-be-crowdstruck\/\">\n<p>The macOS version of the Falcon sensor uses a kernel extension (kext) on Intel Macs prior to Big Sur, but because of the limitations of kexts on Apple silicon, it now uses an endpoint security System Extension instead.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/x.com\/i0n1c\/status\/1814542223687754083\">Stefan Esser<\/a>:<\/p>\n<blockquote cite=\"https:\/\/x.com\/i0n1c\/status\/1814542223687754083\"><p>People pointing to EndpointSecurity framework in MacOS as the solution for the Crowdstrike problem are missing the point. ES is a typical Apple solution and basically means:anyone who can bypass it has to have exactly one exploit (chain) that will allow them to bypass ALL vendors<\/p><p>Sure yes running drivers in user land has less likelihood of taking down the whole system but it also means their functionality is severely limited by what API the vendor provided. Apple is simply gatekeeper in one more area of their devices.<\/p><p>It would be sufficient for OS protection to mark drivers that crash as dirty and if this happens repeatedly boot without the driver and\/or optionally allow a rollback to a previously not crashing configuration<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/spyglass.org\/eu-blue-screen-of-death\/\">M.G. Siegler<\/a>:<\/p>\n<blockquote cite=\"https:\/\/spyglass.org\/eu-blue-screen-of-death\/\">\n<p>The EC obviously felt they were helping out third-parties by requiring Microsoft to continue to grant the same level of kernel access that they have. And perhaps this was even a good thing for end-users as these companies could cover security bases that Microsoft wouldn't, for whatever reason &#x2013; security in general, <a href=\"https:\/\/spyglass.org\/total-recall-microsoft\/\">of course<\/a>, has <a href=\"https:\/\/spyglass.org\/windows-ai-recall-security\/\">not been<\/a> a Microsoft strong suit, <a href=\"https:\/\/www.nytimes.com\/2024\/07\/19\/us\/politics\/crowdstrike-outage.html?ref=spyglass.org\">of late<\/a>. But there are also often unintended consequences of such actions. In this case, a third-party service with a single code-push could take out millions of machines overnight and thus, cripple key infrastructure around the world.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/stratechery.com\/2024\/crashes-and-competition\/\">Ben Thompson<\/a>:<\/p>\n<blockquote cite=\"https:\/\/stratechery.com\/2024\/crashes-and-competition\/\">\n<p>Fast forward nearly two decades, and while Symantec and McAfee are still around, there is a new wave of cloud-based security companies that dominate the space, including CrowdStrike; Windows is much more secure than it used to be, but after the disastrous 2000s, a wave of regulations were imposed on companies requiring them to adhere to a host of requirements that are best met by subscribing to an all-in-one solution that checks all of the relevant boxes, and CrowdStrike fits the bill. What is the same is kernel-level access, and that brings us to last week&rsquo;s disaster.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/x.com\/taviso\/status\/1814762302337654829\">Tavis Ormandy<\/a>:<\/p>\n<blockquote cite=\"https:\/\/x.com\/taviso\/status\/1814762302337654829\"><p>This strange tweet got &gt;25k retweets. The author sounds confident, and he uses lots of hex and jargon. There are red flags though&#8230; like what&rsquo;s up with the DEI stuff, and who says &ldquo;stack trace dump&rdquo;? Let&rsquo;s take a closer look&#8230;<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/threadreaderapp.com\/thread\/1814343502886477857.html\">Patrick Wardle<\/a> (<a href=\"https:\/\/x.com\/patrickwardle\/status\/1814343502886477857\">tweet<\/a>, <a href=\"https:\/\/news.ycombinator.com\/item?id=41021366\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/threadreaderapp.com\/thread\/1814343502886477857.html\"><p>I don&rsquo;t do Windows but here are some (initial) details about why the CrowdStrike&rsquo;s CSAgent.sys crashed.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/x.com\/shipilev\/status\/1814920282638848193\">Aleksey Shipil&euml;v<\/a>:<\/p>\n<blockquote cite=\"https:\/\/x.com\/shipilev\/status\/1814920282638848193\"><p>&ldquo;Professional programmers&rdquo; focusing on CrowdStrike disassembly\/language is a coping mechanism that protects them from realizing that there is a remotely updated 3rd party kernel module that is deployed on significant part of the world. That is why real postmortems are important.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/x.com\/bcantrill\/status\/1814397059224744003\">Bryan Cantrill<\/a>:<\/p>\n<blockquote cite=\"https:\/\/x.com\/bcantrill\/status\/1814397059224744003\"><p>\nThe CrowdStrike BSOD fiasco is extraordinary in its scale and scope; on Monday&rsquo;s Oxide and Friends, \n@ahl\n and I will be joined by security researcher and \n@LutaSecurity\n CEO \n@k8em0\n to help us sort through the many layers of this mess<\/p><\/blockquote>\n\n<p>See also: <a href=\"https:\/\/xkcd.com\/2961\/\">xkcd<\/a>.<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/01\/04\/southwest-airlines-and-technical-debt\/\">Southwest Airlines and Technical Debt<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2020\/11\/23\/requesting-entitlements-still-broken\/\">Requesting Entitlements, Still Broken<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2020\/03\/25\/little-snitch-and-the-deprecation-of-kernel-extensions\/\">Little Snitch and the Deprecation of Kernel Extensions<\/a><\/li>\n<\/ul>\n\n<p id=\"crowdstrike-update-causes-bsod-update-2024-07-23\">Update (2024-07-23): <a href=\"https:\/\/mastodon.social\/@sdw\/112832415242329257\">Sebastiaan de With<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.social\/@sdw\/112832415242329257\">\n<p>Has anyone checked on the App Store backend? Automated reports have been MIA since the Crowdstrike incident. &#x1F440;<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/tidbits.com\/2024\/07\/22\/what-should-apple-users-take-away-from-the-crowdstrike-debacle\/\">Adam Engst<\/a>:<\/p>\n<blockquote cite=\"https:\/\/tidbits.com\/2024\/07\/22\/what-should-apple-users-take-away-from-the-crowdstrike-debacle\/\"><p>Apple devices may not be as vulnerable to a bug in an update to third-party software like CrowdStrike, but that doesn&rsquo;t mean we can be complacent. Apple itself regularly releases updates, and while it&rsquo;s essential to install them to patch security vulnerabilities, Apple&rsquo;s engineers could make a mistake that would cause problems for millions. Howard Oakley&rsquo;s article reminded me of when an Apple update inadvertently disabled Ethernet (see &ldquo;<a href=\"https:\/\/tidbits.com\/2016\/02\/29\/el-capitan-system-integrity-protection-update-breaks-ethernet\/\">El Capitan System Integrity Protection Update Breaks Ethernet<\/a>,&rdquo; 29 February 2016). Apple quickly addressed the problem, but the lack of Ethernet prevented some Macs from getting the revised update, requiring manual intervention.<\/p><p>[&#8230;]<\/p><p>Even if we give CrowdStrike the benefit of the doubt and say that the bug was a subtle mistake that could have slipped by any developer, I can&rsquo;t see any excuse for why it wasn&rsquo;t caught in testing. Either CrowdStrike wasn&rsquo;t doing real-world testing&mdash;the company constantly releases patches like this&mdash;or someone messed up big time.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/www.macrumors.com\/2024\/07\/22\/microsoft-blames-european-commission-for-outage\/\">Juli Clover<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.macrumors.com\/2024\/07\/22\/microsoft-blames-european-commission-for-outage\/\"><p>In a statement to <em>The <a href=\"https:\/\/www.macrumors.com\/guide\/wsj-com\/\">Wall Street Journal<\/a><\/em>, Microsoft blamed the European Commission for an inability to offer the same protections that Macs have. Microsoft said that it is unable to wall off its operating system because of an &ldquo;understanding&rdquo; with the European Commission. <a href=\"https:\/\/news.microsoft.com\/2009\/12\/16\/microsoft-statement-on-european-commission-decision\/\">Back in 2009<\/a>, Microsoft agreed to interoperability rules that provide third-party security apps with the same level of access to Windows that Microsoft gets. Microsoft agreed to provide kernel access in order to resolve multiple longstanding competition law issues in Europe.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/mastodon.online\/@tclementdev\/112831906505665551\">Thomas Clement<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.online\/@tclementdev\/112831906505665551\">\n<p>Nothing prevents Microsoft and Crowdstrike from developing and adopting a user space solution if they so wish. But they didn't.<\/p>\n<p>Also I'd like to point out that it is totally possible to completely deadlock macOS with user space endpoint security.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/pxlnv.com\/linklog\/crowdstrike-fallout\/\">Nick Heer<\/a>:<\/p>\n<blockquote cite=\"https:\/\/pxlnv.com\/linklog\/crowdstrike-fallout\/\">\n<p>If one has a general worldview for technology today, they can find it in <a href=\"https:\/\/mjtsai.com\/blog\/2024\/07\/22\/crowdstrike-update-causes-bsod\/\">some analysis of this CrowdStrike failure<\/a>. This saga has everything.<\/p>\n<\/blockquote>\n\n<p id=\"crowdstrike-update-causes-bsod-update-2024-07-24\">Update (2024-07-24): <a href=\"https:\/\/www.youtube.com\/watch?v=5XTQd_MGkvM\">Oxide Computer Company<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.youtube.com\/watch?v=5XTQd_MGkvM\">\n<p>Bryan and Adam were joined by security expert, Katie Moussouris, to discuss the largest global IT outage in history. It was an event as broadly impactful as it will be instructive; as Bryan noted, you can see all of computing from here, from crash dumps to antitrust.<\/p>\n<\/blockquote>\n\n<p id=\"crowdstrike-update-causes-bsod-update-2024-07-26\">Update (2024-07-26): <a href=\"https:\/\/www.schneier.com\/blog\/archives\/2024\/07\/the-crowdstrike-outage-and-market-driven-brittleness.html\">Bruce Schneier and Barath Raghavan<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.schneier.com\/blog\/archives\/2024\/07\/the-crowdstrike-outage-and-market-driven-brittleness.html\">\n<p>The catastrophe is yet another reminder of how brittle global internet infrastructure is. It&rsquo;s complex, deeply interconnected, and filled with single points of failure. As we experienced last week, a single problem in a small piece of software can take large swaths of the internet and global economy offline.<\/p>\n<p>The brittleness of modern society isn&rsquo;t confined to tech. We can see it in many parts of our infrastructure, from <a href=\"https:\/\/www.fda.gov\/food\/sampling-protect-food-supply\/microbiological-surveillance-sampling-fy22-23-farm-inspections-and-sampling-leafy-greens-grown#_ftn2\">food<\/a> to <a href=\"https:\/\/energy.utexas.edu\/research\/ercot-blackout-2021\">electricity<\/a>, from <a href=\"https:\/\/insight.kellogg.northwestern.edu\/article\/what-went-wrong-at-aig\">finance<\/a> to <a href=\"https:\/\/www.nytimes.com\/2024\/03\/27\/us\/baltimore-bridge-collapse.html\">transportation<\/a>. This is often a result of globalization and consolidation, but not always. In information technology, brittleness also results from the fact that hundreds of companies, none of which you;ve heard of, each perform a small but essential role in keeping the internet running. CrowdStrike is one of those companies.<\/p>\n<p>This brittleness is a result of market incentives. In enterprise computing&mdash;as opposed to personal computing&mdash;a company that provides computing infrastructure to enterprise networks is incentivized to be as integral as possible, to have as deep access into their customers&rsquo; networks as possible, and to run as leanly as possible.<\/p>\n<\/blockquote>\n\n<p id=\"crowdstrike-update-causes-bsod-update-2024-07-29\">Update (2024-07-29): <a href=\"https:\/\/www.lutasecurity.com\/post\/re-learning-lessons-from-the-crowdstrike-outage\">Katie Moussouris<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.lutasecurity.com\/post\/re-learning-lessons-from-the-crowdstrike-outage\">\n<p>The cause of the most significant internet outage event in history was a cascade of failures in both testing and deployment capability. The technical bugs in the testing and the client-side interpreter code are one area for improvement, and the process failures that propagated this so widely and quickly are another. Both functional areas need to be addressed to ensure we don&rsquo;t have to endure an outage of this magnitude again.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/x.com\/patrickwardle\/status\/1816169307770065211\">Patrick Wardle<\/a>:<\/p>\n<blockquote cite=\"https:\/\/x.com\/patrickwardle\/status\/1816169307770065211\"><p>I was rather skeptical that this wasn&rsquo;t an elaborate joke, but yes, \n@CrowdStrike\n has apparently emailed its customers &amp; offered a ~$10 UberEats gift card\/coupon for any &ldquo;inconvenience&rdquo; <\/p><p>&#8230;and yes, it errors out when one goes to redeem it, saying it has been cancelled &#x1FAE0;<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/x.com\/1Br0wn\/status\/1817618124319207532\">Ian Brown<\/a>:<\/p>\n<blockquote cite=\"https:\/\/x.com\/1Br0wn\/status\/1817618124319207532\">\n<p>ANOTHER <a href=\"https:\/\/ft.com\/content\/60dde560-194a-40d1-8c98-1d96d6d019a0\">opinion piece<\/a> repeating Microsoft&rsquo;s claim the EU is responsible for the #CrowdStrike debacle. You can read the &ldquo;interoperability undertaking&rdquo; Microsoft made in 2009 yourself&#8230; no, it does NOT require kernel access for Windows competitors.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/07\/27\/windows-security-best-practices-for-integrating-and-managing-security-tools\/\">Microsoft<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=41095530\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/07\/27\/windows-security-best-practices-for-integrating-and-managing-security-tools\/\">\n<p>In this blog post, we examine the recent CrowdStrike outage and provide a technical overview of the root cause. We also explain why security products use kernel-mode drivers today and the safety measures Windows provides for third-party solutions. In addition, we share how customers and security vendors can better leverage the integrated security capabilities of Windows for increased security and reliability. Lastly, we provide a look into how Windows will enhance extensibility for future security products.<\/p>\n<\/blockquote>\n\n<p id=\"crowdstrike-update-causes-bsod-update-2024-07-30\">Update (2024-07-30): <a href=\"https:\/\/www.osnews.com\/story\/140301\/no-southwest-airlines-is-not-still-using-windows-3-1\/\">Thom Holwerda<\/a> (via <a href=\"https:\/\/pxlnv.com\/linklog\/southwest-windows-debunk\/\">Nick Heer<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.osnews.com\/story\/140301\/no-southwest-airlines-is-not-still-using-windows-3-1\/\">\n<p>It turned out be a troll tweet. A <a href=\"https:\/\/x.com\/ArtemR\/status\/1814367821943713960\">reply to the tweet by Russakovskii<\/a> a day later made that very lear: &ldquo;To be clear, I was trolling last night, but it turned out to be true. Some Southwest systems <a href=\"https:\/\/paop.org\/news\/f\/point-to-point-of-failure-how-southwest-airlines-melted-down\">apparently do run Windows 3.1<\/a>. lol.&rdquo;<\/p>\n<p>[&#8230;]<\/p>\n<p>These few paragraphs do not say that Southwest is still using ancient Windows versions; it just states that the systems they developed internally, SkySolver and Crew Web Access, <em>look<\/em> &ldquo;historic like they were designed on Windows 95&rdquo;. The fact that they are also available as mobile applications should further make it clear that no, these applications are not running on Windows 3.1 or Windows 95. Southwest pilots and cabin crews are definitely not carrying around pocket laptops from the &rsquo;90s.<\/p>\n<p>These paragraphs were then misread, misunderstood, and mangled in a game of social media and bad reporting telephone, and here we are.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/www.cnbc.com\/2024\/07\/29\/delta-hires-david-boies-to-seek-damages-from-crowdstrike-microsoft-.html\">Jordan Novet and Ari Levy<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.cnbc.com\/2024\/07\/29\/delta-hires-david-boies-to-seek-damages-from-crowdstrike-microsoft-.html\"><p>Delta has hired prominent attorney David Boies to pursue potential damages from CrowdStrike and Microsoft after a mass outage earlier this month, CNBC&rsquo;s Phil Lebeau reported on Monday.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/heavymeta.org\/2024\/07\/28\/crowdstrikes-impact-on-aviation.html\">John Wiseman<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=41103101\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/heavymeta.org\/2024\/07\/28\/crowdstrikes-impact-on-aviation.html\">\n<p>Airline cancellations is a good metric, but I want to look directly at air traffic: How many planes were in the air? How many planes should have been in the air?<\/p>\n<\/blockquote>\n\n<p id=\"crowdstrike-update-causes-bsod-update-2024-07-31\">Update (2024-07-31): <a href=\"https:\/\/www.bitsaboutmoney.com\/archive\/crowdstrike-bug-hit-banks-hard\/\">Patrick McKenzie<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=41119874\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.bitsaboutmoney.com\/archive\/crowdstrike-bug-hit-banks-hard\/\">\n<p>It would be an overstatement to say that the United States federal government commanded U.S. financial institutions to install CrowdStrike Falcon and thereby embed a landmine into the kernels of all their employees&rsquo; computers. Anyone saying that has no idea how banking regulation works.<\/p>\n<p>[&#8230;]<\/p>\n<p>Does the FFEITC have a hugely prescriptive view of what you should be doing for malware monitoring? Well, no [&#8230;]But your consultants will tell you that you want a very responsive answer to II.C.12 in this report and that, since you probably do not have Google&rsquo;s ability to fill floors of people doing industry-leading security research, you should just buy something which says Yeah We Do That. <\/p>\n<p>CrowdStrike&rsquo;s sales reps will happily tell you <a href=\"https:\/\/crowdstrike.com\/solutions\/financial-services\/\">Yeah We Do That<\/a>.<\/p>\n<\/blockquote>\n\n<p id=\"crowdstrike-update-causes-bsod-update-2024-08-14\">Update (2024-08-14): See also: <a href=\"https:\/\/atp.fm\/598\">Accidental<\/a> <a href=\"https:\/\/atp.fm\/599\">Tech Podcast<\/a>.<\/p>\n\n<p id=\"crowdstrike-update-causes-bsod-update-2024-09-17\">Update (2024-09-17): <a href=\"https:\/\/www.semafor.com\/article\/09\/12\/2024\/ex-crowdstrike-employees-detail-rising-technical-errors-before-july-outage\">Rachyl Jones<\/a> (via <a href=\"https:\/\/news.ycombinator.com\/item?id=41534716\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.semafor.com\/article\/09\/12\/2024\/ex-crowdstrike-employees-detail-rising-technical-errors-before-july-outage\">\n<p>Software engineers at the cybersecurity firm CrowdStrike complained about rushed deadlines, excessive workloads, and increasing technical problems to higher-ups for more than a year before a catastrophic failure of its software paralyzed airlines and knocked banking and other services offline for hours.<\/p>\n<p>&ldquo;Speed was the most important thing,&rdquo; said Jeff Gardner, a senior user experience designer at CrowdStrike who said he was laid off in January 2023 after two years at the company. &ldquo;Quality control was not really part of our process or our conversation.&rdquo;<\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Rory Tingle et al.: The &lsquo;most serious IT outage the world has ever seen&rsquo; sparked global chaos today - with planes and trains halted, the NHS disrupted, shops closed, football teams unable to sell tickets and banks and TV channels knocked offline. See also: Reddit, Hacker News, and Slashdot. Qasim Nauman (Hacker News): Frontier Airlines [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2024-07-22T18:16:07Z","apple_news_api_id":"649a4ea9-5c6b-4183-b705-6de177757bfc","apple_news_api_modified_at":"2024-09-17T13:55:21Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAADg==","apple_news_api_share_url":"https:\/\/apple.news\/AZJpOqVxrQYO3BW3hd3V7_A","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[1198,131,2626,1927,1918,828,209,448,30,2385,856,48,219],"class_list":["post-44179","post","type-post","status-publish","format-standard","hentry","category-technology","tag-airplane","tag-bug","tag-crowdstrike","tag-european-union","tag-health","tag-kernel-extensions","tag-legal","tag-linux","tag-mac","tag-macos-14-sonoma","tag-microsoft-azure","tag-security","tag-windows"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/44179","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=44179"}],"version-history":[{"count":16,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/44179\/revisions"}],"predecessor-version":[{"id":44897,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/44179\/revisions\/44897"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=44179"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=44179"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=44179"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}