imagladry
About
- Username
- imagladry
- Joined
- Visits
- 48
- Last Active
- Roles
- member
- Points
- 86
- Badges
- 0
- Posts
- 106
Reactions
-
Microsoft blames European Commission for global CrowdStrike catastrophe
ianbetteridge said:M68000 said:This seems to be totally a QA testing issue. Was any testing done?So the answer to this is, "it's complicated". Some of this is going to be a bit simplified, but it's accurate enough.Software on Windows can run in two modes: kernel mode; and user mode. User mode software shouldn't ever be able to cause a BSOD.Security software needs to run in kernel mode. There are good reasons for this: malware often hides deep in the OS in places where user mode software can't find it. CrowdStrike Falcon works like a device drive, which allows it to reside in kernel mode and access system data structures and services."Heck," you're thinking, "so can anyone write a device driver and get their software running in kernel mode?" Well, no: Windows will display a warning unless a driver has passed Microsoft's WHQL testing process. In some cases, Windows won't even allow the driver to run.
Falcon is WHQL certified, so it *should* be pretty robust and not cause a BSOD. But there's a catch: it relies on dynamic definition files, which are deployed to update its configuration. From what I hear, Crowdstrike accidentally deployed one which contained nothing but zeros, which led to a catastrophic error. In other words, they simply deployed the wrong file. No testing will catch that -- it's a file that wasn't meant to be deployed at all.ianbetteridge said:M68000 said:This seems to be totally a QA testing issue. Was any testing done?So the answer to this is, "it's complicated". Some of this is going to be a bit simplified, but it's accurate enough.Software on Windows can run in two modes: kernel mode; and user mode. User mode software shouldn't ever be able to cause a BSOD.Security software needs to run in kernel mode. There are good reasons for this: malware often hides deep in the OS in places where user mode software can't find it. CrowdStrike Falcon works like a device drive, which allows it to reside in kernel mode and access system data structures and services."Heck," you're thinking, "so can anyone write a device driver and get their software running in kernel mode?" Well, no: Windows will display a warning unless a driver has passed Microsoft's WHQL testing process. In some cases, Windows won't even allow the driver to run.
Falcon is WHQL certified, so it *should* be pretty robust and not cause a BSOD. But there's a catch: it relies on dynamic definition files, which are deployed to update its configuration. From what I hear, Crowdstrike accidentally deployed one which contained nothing but zeros, which led to a catastrophic error. In other words, they simply deployed the wrong file. No testing will catch that -- it's a file that wasn't meant to be deployed at all.
<blockquote>In other words, they simply deployed the wrong file. No testing will catch that -- it's a file that wasn't meant to be deployed at all. <blockquote>
As some who has written installation packages, with any company worth their salt, the install package goes through testing, also. That would have caught the zero file. -
'Making Apple Vision Pro' video delves into precise aluminum cutting & assembly
-
MagSafe on the new MacBook Pro: Everything you need to know
-
iPhone SE returns to Apple's clearance store for third time in January
DAalseth said:maciekskontakt said:This would be great if they kept size and upgraded processor. Their support will end soon and $300 might be waste of money. Having hardware upgraded phone for $500 that would be supported for next 4 years would be much better option. I was personally in the situation like that and as much as I like iPhone SE and its attractive price I will not buy it because of limited time support. I upgrade mobile phones every 4-5 years. I do not care what others do and I definitely do not have time for playing phone upgrades and hype - this only tool for me. So to keep cost efficiency and upgrade I went Android LG which offers solid functions (some quality is way better than newest iPhone's like screen and sound). Sorry Apple, but that was good run with 5S for last years. No more and absolutely nothing that exceeds $600 price mark for phone. -
Apple Silicon transition may hit its two-year target with 2022 Mac Pro
mike54 said:After all the unlimited praise youtubers, tech sites, Apple fanboius, etc gave the M1, I just hope Apple is not taking advantage of this praise, milking as much revenue as they can from it, thereby delaying advancement. Apple does have a bad habit of releasing something great and then sitting on it past its use-by date.
-
Saudi Arabia passes law requiring USB-C charges for smartphones
-
Zuckerberg thinks Apple is making aggressive moves now to control the metaverse
-
Apple introduces iOS 16 with a revamped widget-covered lock screen, Wallet and Map changes...
-
Apple culture hinders recruitment and talent retention efforts, report says
-
Apple hit with lawsuit targeting AppleCare+ refurbished devices
Looks like I got lied to. My wife's out of warranty iPhone 5c died and was offered a "new" replacement. I asked if the phone was new? I got told yes. Not refurbished? I got told no, it is new. Sucker died in 6 months and store will not stand behind it. Lied to 3 different times.