Oxide and Friends 7/24/2024 -- CrowdStrike BSOD Fiasco with Katie Moussouris

Поділитися
Вставка
  • Опубліковано 21 жов 2024
  • Bryan and Adam were joined by security expert, Katie Moussouris, to discuss the largest global IT outage in history. It was an event as broadly impactful as it will be instructive; as Bryan noted, you can see all of computing from here, from crash dumps to antitrust.
    Context: mastodon.socia...
    Notes: github.com/oxi...

КОМЕНТАРІ • 10

  • @admalledd
    @admalledd 2 місяці тому +4

    Thank you for having Katie on! As she mentions, the CSRB reports are wonderful for pushing corp changes that have just really needed that ammo in the correct language. The Log4j report specifically we were able to use to finally get some (semi) centralized/monitored list of every library all our platforms so we could track versions used better, to ensure when a CVE (or whatever) needed us to patch/update, we could actually ensure we found all required systems. It was known for a while that such info would be useful by us handling day to day, but justifying the initial costs etc...

  • @Tim_Small
    @Tim_Small 2 місяці тому +1

    On 1st January 2000, at about half past midnight I remember phoning my Silicon Valley friends and former house mates from a nightclub in the UK to let them know nothing catastrophic appeared to have gone down (or at least the music and the bar was still working). Plus, of course, how often do you get to call somebody in a different millennia to you?

  • @rotors_taker_0h
    @rotors_taker_0h 2 місяці тому +1

    Katie is such a great guest. And has such a polite way to describe this absolute shit show of crowdstrike testing and rollouts processes.

  • @Don__
    @Don__ 2 місяці тому +2

    I've seen it mentioned that microsoft doesn't have to give kernel access. They just have to give the same access that their tools are using. So building a security API and having defender use that should be allowed.

  • @capability-snob
    @capability-snob 2 місяці тому

    "he makes some mistakes, but he says them with such confidence"
    I have no opinion on Dave but this is such a great quote, thanks Katie

  • @THB192
    @THB192 2 місяці тому +1

    Funnily enough there was a Linux CrowdStrike incident prior to this and on Linux CrowdStrike actually does run under eBPF.

  • @ivthgatekeeper
    @ivthgatekeeper 2 місяці тому +1

    1:30:14 "it wasn't that corporations weren't giving enough resources to open source projects, it's that they didn't know which ones would become important" this is word by word the issue (although not the only relevant one) at the heart of the xz backdoor attack as well, in the sense that there is limited visibility on semi-abandoned projects or struggling maintainers

  • @jamesfmilne
    @jamesfmilne 3 місяці тому +1

    My first dog was called Mac for Macintosh.

  • @pmcgee003
    @pmcgee003 2 місяці тому +1

    How did the us get the terrible title 'Airplane' when in real countries it was 'Flying High' ? 😅