Hacker News new | past | comments | ask | show | jobs | submit login
CrowdStrike IT Outage Explained by a Windows Developer [video] (youtube.com)
23 points by Rinzler89 4 months ago | hide | past | favorite | 4 comments



The title should probably say "former" Windows developer. Dave hasn't worked at Microsoft in over 20 years (he left in 2003)

It's probably also worth noting he's a serial liar who claims he wrote Space Cadet Pinball [1] and that "Linux has binary blobs that only Linus Torvalds has the source code to [2]

Also there was that time he got sued by the Washington State Attorney General for selling "Registry Cleaner" and "Internet Shield" junk apps [3]

I don't consider Dave a credible source for much of anything and the amount of clickbait he pumps out for Youtube in recent years has only solidified that opinion

[1] https://social.restless.systems/system/media_attachments/fil...

[2] https://social.restless.systems/system/media_attachments/fil...

[3] https://www.atg.wa.gov/news/news-releases/attorney-general-s...


The "all this debugging was done in assembly language with minimal symbol table information" was basically true in 2009-2011 too. The (non-CrowdStrike, non-Microsoft) team I was on was developing Windows intermediate drivers which did network acceleration. I'm not sure how CrowdStrike works but we essentially MITM'd/proxied in the Windows networking stack (is CrowdStrike observe-only? I don't know). I would end up filling notebooks with register moves and subroutine calls to trace back bluescreens because Windows is closed source. Thank goodness for Windbag disassembly. Interop with other intermediate drivers like popular virus scanners was an interesting problem. I'm pretty proud of our work there in hindsight!


11:00 mark nailed it pretty much how many engineers here doesn't simply understand and blames Microsoft. I refrained from commenting earlier because people don't see these during chaos mode.


I want to know more about why the update was pushed to every single machine online at that time, ignoring CS sensor update policies that admins use to update test network first, before updating production.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: