Calgarypuck Forums - The Unofficial Calgary Flames Fan Community

Go Back   Calgarypuck Forums - The Unofficial Calgary Flames Fan Community > Main Forums > The Off Topic Forum
Register Forum Rules FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Search this Thread
Old 07-19-2024, 11:38 AM   #61
Fuzz
Franchise Player
 
Fuzz's Avatar
 
Join Date: Mar 2015
Location: Pickle Jar Lake
Exp:
Default

Quote:
Originally Posted by nfotiu View Post
How did an update like this hit every server worldwide at the same time?
If this is true, it's the usual foe. Incompetence.


Quote:
What happened here was they pushed a new kernel driver out to every client without authorization to fix an issue with slowness and latency that was in the previous Falcon sensor product. They have a staging system which is supposed to give clients control over this but they pissed over everyone's staging and rules and just pushed this to production.
https://news.ycombinator.com/item?id=41003390
Fuzz is offline   Reply With Quote
The Following User Says Thank You to Fuzz For This Useful Post:
Old 07-19-2024, 11:43 AM   #62
KelVarnsen
Franchise Player
 
KelVarnsen's Avatar
 
Join Date: Jul 2010
Location: Apartment 5A
Exp:
Default

How very Rogers of them
KelVarnsen is offline   Reply With Quote
The Following User Says Thank You to KelVarnsen For This Useful Post:
Old 07-19-2024, 11:44 AM   #63
Blaster86
UnModerator
 
Blaster86's Avatar
 
Join Date: Dec 2004
Location: North Vancouver, British Columbia.
Exp:
Default

That's a whoopsie-oopsie.
__________________

THANK MR DEMKO
CPHL Ottawa Vancouver
Blaster86 is online now   Reply With Quote
Old 07-19-2024, 11:46 AM   #64
Reggie Dunlop
All I can get
 
Reggie Dunlop's Avatar
 
Join Date: Oct 2001
Exp:
Default

Reggie Dunlop is offline   Reply With Quote
The Following 4 Users Say Thank You to Reggie Dunlop For This Useful Post:
Old 07-19-2024, 12:05 PM   #65
Firebot
#1 Goaltender
 
Join Date: Jul 2011
Exp:
Default

Quote:
Originally Posted by Fuzz View Post
If this is true, it's the usual foe. Incompetence.



https://news.ycombinator.com/item?id=41003390
"Who needs change mangement and processes when I want to go on vacation early? Just push it no one will notice"

CIO will likely be forced to resign, in the end processes and security measures are built from the top down.
Firebot is offline   Reply With Quote
Old 07-19-2024, 12:12 PM   #66
Fuzz
Franchise Player
 
Fuzz's Avatar
 
Join Date: Mar 2015
Location: Pickle Jar Lake
Exp:
Default

Quote:
Originally Posted by Firebot View Post
"Who needs change mangement and processes when I want to go on vacation early? Just push it no one will notice"

CIO will likely be forced to resign, in the end processes and security measures are built from the top down.
The CEO won't be racing his car today, that's for sure.


https://www.theautopian.com/think-yo...-this-weekend/
Fuzz is offline   Reply With Quote
Old 07-19-2024, 12:18 PM   #67
nik-
Franchise Player
 
nik-'s Avatar
 
Join Date: Jun 2004
Exp:
Default

Quote:
Originally Posted by Fuzz View Post
The CEO won't be racing his car today, that's for sure.


https://www.theautopian.com/think-yo...-this-weekend/
What a dumb article lol. CEO has hobby and he isn't doing it today. Ok?
__________________
Quote:
Originally Posted by MisterJoji View Post
Johnny eats garbage and isn’t 100% committed.
nik- is offline   Reply With Quote
The Following User Says Thank You to nik- For This Useful Post:
Old 07-19-2024, 12:19 PM   #68
Fuzz
Franchise Player
 
Fuzz's Avatar
 
Join Date: Mar 2015
Location: Pickle Jar Lake
Exp:
Default

Quote:
Originally Posted by nik- View Post
What a dumb article lol. CEO has hobby and he isn't doing it today. Ok?
It's a car site, they need to leverage the connection to a massive news story somehow. Doin' it for the clicks!
Fuzz is offline   Reply With Quote
Old 07-19-2024, 12:20 PM   #69
Erick Estrada
Franchise Player
 
Erick Estrada's Avatar
 
Join Date: Oct 2006
Location: San Fernando Valley
Exp:
Default

LOL I take the afternoon off today to do estate stuff getting checks to pay charities, beneficiaries, etc and of course I walk into TD bank and they are down. Oh well it's a nice afternoon to go do something else I guess.
Erick Estrada is offline   Reply With Quote
Old 07-19-2024, 12:28 PM   #70
activeStick
Franchise Player
 
activeStick's Avatar
 
Join Date: Jan 2014
Exp:
Default

Quote:
Originally Posted by nfotiu View Post
How did an update like this hit every server worldwide at the same time?
I'm guessing some genius decided his code change was good and pushed it direct to prod
activeStick is offline   Reply With Quote
Old 07-19-2024, 02:39 PM   #71
Firebot
#1 Goaltender
 
Join Date: Jul 2011
Exp:
Default

It's absolutely mind boggling just how massive of an disaster this is. This will take some enterprises weeks to figure out and fix in some instances and in some cases may not be possible. You can't send updates to a PC that is in a BSOD loop and you cannot do the workaround fix if it cannot get in safe mode (Bitlocker).

This is like the ultimate cybersecurity incident. You can bet companies around the world will be reviewing their BCP and disaster recovery plans on Monday.
Firebot is offline   Reply With Quote
Old 07-19-2024, 02:54 PM   #72
Bigtime
Franchise Player
 
Bigtime's Avatar
 
Join Date: Apr 2008
Location: Calgary
Exp:
Default

Our POS provider just supplied another update, they figure another 5-6 hours to really get things back to normal. Despite the fixes supplied by Crowdstrike and Microsoft there is a lot of additional troubleshooting and remediation required.
Bigtime is offline   Reply With Quote
Old 07-19-2024, 02:54 PM   #73
Fuzz
Franchise Player
 
Fuzz's Avatar
 
Join Date: Mar 2015
Location: Pickle Jar Lake
Exp:
Default

I don't think there are any systems that can't be fixed, it is just a pain. Even the bitlocker ones can be done without the bitlocker key by using bcdedit.

Quote:
  1. Cycle through BSODs until you get the recovery screen.
  2. Navigate to Troubleshoot > Advanced Options > Startup Settings
  3. Press Restart
  4. Skip the first Bitlocker recovery key prompt by pressing Esc
  5. Skip the second Bitlocker recovery key prompt by selecting Skip This Drive in the bottom right
  6. Navigate to Troubleshoot > Advanced Options > Command Prompt
  7. Type bcdedit /set {default} safeboot minimal. then press enter.
  8. Go back to the WinRE main menu and select Continue.
  9. It may cycle 2-3 times.
  10. If you booted into safe mode, log in per normal.
  11. Open Windows Explorer, navigate to C:\Windows\System32\drivers\Crowdstrike
  12. Delete the offending file (STARTS with C-00000291*. sys file extension)
  13. Open command prompt (as administrator)
  14. Type bcdedit /deletevalue {default} safeboot, then press enter. 5. Restart as normal, confirm normal behavior.
https://old.reddit.com/r/crowdstrike...strike_update/


But questions will be asked(yelled).
Fuzz is offline   Reply With Quote
Old 07-19-2024, 03:27 PM   #74
Firebot
#1 Goaltender
 
Join Date: Jul 2011
Exp:
Default

Quote:
Originally Posted by Fuzz View Post
I don't think there are any systems that can't be fixed, it is just a pain. Even the bitlocker ones can be done without the bitlocker key by using bcdedit.
Yes sure, but do this 5000 times physically on each device at a larger size company on a Friday where most people are working from home and staff are on vacation and have branch offices across the country with outsourced IT
Firebot is offline   Reply With Quote
Old 07-19-2024, 03:30 PM   #75
Fuzz
Franchise Player
 
Fuzz's Avatar
 
Join Date: Mar 2015
Location: Pickle Jar Lake
Exp:
Default

Oh, it's absolutely a disaster, I just don't think it's an unsolvable data loss event. I do think some people will be reconsidering where their bitlocker keys get stored, though.
Fuzz is offline   Reply With Quote
The Following User Says Thank You to Fuzz For This Useful Post:
Old 07-19-2024, 03:33 PM   #76
chemgear
Franchise Player
 
Join Date: Feb 2010
Exp:
Default

Quote:
Originally Posted by activeStick View Post
I'm guessing some genius decided his code change was good and pushed it direct to prod
#### it, hit enter and leave early for the weekend!
chemgear is offline   Reply With Quote
Old 07-19-2024, 05:12 PM   #77
Shazam
Franchise Player
 
Shazam's Avatar
 
Join Date: Aug 2005
Location: Memento Mori
Exp:
Default

Quote:
Originally Posted by Azure View Post
Absolutely ####ing hilarious.
__________________
If you don't pass this sig to ten of your friends, you will become an Oilers fan.
Shazam is offline   Reply With Quote
Old 07-19-2024, 09:14 PM   #78
woob
#1 Goaltender
 
woob's Avatar
 
Join Date: Jan 2006
Exp:
Default

A friend's company got hit by this here in town. 500+ systems. Their team started fixing around 7am and finished up around 6pm. He said it was mind numbing work, entering BL keys for approx 11 hours. Happy to have it all sorted, but I'm sure there's a seething, underlying rage for CrowdStrike within their team.
woob is offline   Reply With Quote
Old 07-19-2024, 10:10 PM   #79
Firebot
#1 Goaltender
 
Join Date: Jul 2011
Exp:
Default

Have to feel for this guy.

https://www.reddit.com/r/crowdstrike...t=share_button
Firebot is offline   Reply With Quote
Old 07-20-2024, 08:34 AM   #80
Azure
Had an idea!
 
Azure's Avatar
 
Join Date: Oct 2005
Exp:
Default

Protect yourself from ransomware by installing Crowdstrike!

Except when Crowdstrike decides they have no clue what they're doing and BSODs your entire IT infrastructure just because they can!

Reading the posts on Reddit where IT staff are dealing with this, goodness sake. Crowdstrike should get sued to oblivion and die in a fire.
Azure is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -6. The time now is 01:43 AM.

Calgary Flames
2024-25




Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright Calgarypuck 2021 | See Our Privacy Policy