Ask Noah Show 400 | Open Source Crowdstike Alternative
Jul 24, 2024
auto_awesome
Podcast discusses the Crowdstrike outage affecting 8.5 million Windows machines. Topics include open source solutions, preventing catastrophes, Linux crash restoration, System76's Cosmic DE alpha release, and the importance of backup plans and open source software.
Software updates can cause global outages with severe impacts, highlighting the critical importance of system stability.
Distinguishing between kernel and user mode software execution is crucial to prevent system-wide crashes and ensure stringent controls for critical processes.
CrowdStrike's faulty software update led to a worldwide outage affecting millions of Windows computers, including critical sectors such as healthcare and transportation. The defect in Falcon Sensor resulted in blue screens, rendering 8.5 million machines unusable, grounding people globally. The incident has been labeled as the largest IT disaster, highlighting the criticality of software updates and their impacts on system stability.
Kernel Level vs. User Mode: The Impact of Software Code Execution
The podcast delves into the essential distinction between kernel level and user mode software execution. The kernel interacts directly with hardware and critical system processes, while user mode operates on top of the kernel, making requests for memory or CPU access. Errors at the kernel level can cause system-wide crashes, emphasizing the need for stringent controls and permissions for software running at this critical level.
Endpoint Protection Evolution to XDR and Anticipated Threat Detection
The evolution of cybersecurity protection from reactive approaches like antivirus to proactive strategies such as Extended Detection and Response (XDR) is discussed. Instead of solely reacting to threats, modern solutions aim to predict and prevent them, requiring advanced monitoring and response mechanisms. Companies are compelled to adopt proactive solutions like XDR to remain ahead of evolving cybersecurity challenges.
System Stability and Security: Wazuh's User-Space Focus
The podcast highlights Wazuh's open-source security platform's emphasis on user-space operation as a key factor in enhancing system stability and security. By avoiding direct kernel access and utilizing standard APIs, Wazuh minimizes system crashes and ensures compatibility and easier debugging. Its transparency, community collaboration, and flexibility make it a reliable alternative to traditional kernel-based security solutions like CrowdStrike.
This week Noah takes you through what happened with the Crowdstrike incident, and how you could prevent a similar catastrophe with free and open source software. System76 announces a release date for Cosmic DE alpha. The Immich team is.
-- During The Show --
Crowd Strike Outage
Caused by defective update
Affected all Windows computers
8.5 Million Windows machines rendered unusable
Flights grounded
Entire health care sectors shut down
Kernel vs User mode
WHQL Certification
Crowd Strike had a WHQL Certification
Anti-virus
Extended Detection and Response (XDR) and/or anticipated threat detection
Channel Files
Microsoft could have provided an API
EU requires Microsoft to provide the same access Windows
No checks on the channel file
Crowd Strike Falcon set as "boot-start driver"
April 21st 2010 McAfee deleted svchost.exe
George Kurtz CEO at both McAfee and Crowd Strike during the incidents
Need more help than a radio show can offer? Altispeed provides commercial IT services and they’re excited to offer you a great deal for listening to the Ask Noah Show. Call today and ask about the discount for listeners of the Ask Noah Show!