Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror

Comment Re: Dumb Dumb Dumb (Score 4, Informative) 115

What you and a lot of the other amateurs posting are missing is that this was NOT a Windows update.
None of the Windows update mechanisms were involved so probably half the comments on this story are just plain wrong.

Some method of accessing the file system that bypasses the normal Windows security methods is needed whether that is Safe Mode or booting WinRE.

If a system is encrypted (bitlocker or any other full-disk encryption product) will need a key entered to access the data either way.

The automatic update process that installed the file is Crowdstrike and this is completely separate from Windows updates.
More like an av product auto-updating anti-virus definitions.

As for *nix and *BSD - both do have innately better security but are NOT totally free from this type of issue. It just hasn't happened yet.
And even is it does would not be likely to be as devastating.

Comment Re:I'm more interested (Score 1) 118

Tell that to all the folks I know whose backend servers/VMs have to be rebooted into safe mode manually just to get their domains and production servers back online.

Here is the big kicker to me:
All the large companies that are NOT using some type of lights out/out of band controllers with a remote console on critical production systems.

I fixed 22 or 23 servers yesterday working from my home office.

Comment Re:How about failover to backup servers? (Score 2) 155

Typically software like Crowdstrike is deployed on servers and automatically applies updates, and there ARE valid reasons for that:
their primary purpose is to protect systems from bad actors/malicious penetration attempts.

The defense is basically always a step behind.
These frequent updates are a way of staying just a step behind rather than a leap.

That said - it IS stupid to have critical production systems updated without control.
Just like any prudent enterprise has a lab/testing environment that can have patches applied and vetted before rolling out to production - even if for just a day or two - software that does endpoint protection should provide the same level of control.

But I have not seen any at THAT level that do so. They create their definition/code updates and just push them out.
This would be fine - IF they exercised proper due diligence and tested the code themselves before releasing but as we have seen this is not always the case.

Note that the Crowdstrike debacle did not cause me or my employer any direct issues - but it did for a number of our customers.
Some of whom will be paying us a lot of money to get local technician to their sites to get servers back online since a lot of them also think having centralized IT without local resources is a good idea.

Endpoint Protection has grown tremendously in recent years but is not a mature field and really - none of the companies doing it really do it "smart" and few of the CIOs out there know more than buzzwords so they just aren't aware of stuff like this.

Until now.

Comment Rare proof that the US legal system works (Score 0) 6

Very happy to hear of this verdict.
Rich white men who commit crimes all too often are able to buy their way out and we have all seen Trump trying to buy and lie his way out of this.
But he has failed.

We have a lot of problems in this country but this is a sign that all may NOT be lost after all.

Comment Pretty obvious (Score 1) 157

That Russia, China and North Korea will do all the can to de-stabilize the US of A.

Anything they can do to weaken the US internally will also weaken us on a global level.

They will continue to hack and spread disinformation about Biden in order to try and get Trump elected since that is the best way to further the continued downfall of the United States of America.

Unfortunately a large segment of the US populace already believes the garbage spewing forth from the far-right.

Hopefully there are enough folks in this country paying attention to keep us a free nation and relegate Trump to where he belongs: a footnote in history as the only US president to commit sedition and try to overthrow the elected government.

Comment And many are under-qualified (Score 1) 266

And a degree has never guaranteed a high paying job.
All a college degree has ever done is:
a) open some doors that would otherwise be closed
b) increase probable pay potential after a period of time (typically 8-10 years after graduation)

These things are often still true though possibly less than they used to be in some fields.

The main driver of the "need" for a college education is the desire to not do manual labor or even skilled trades in the US and a contributing factor is that the US economy is no longer based on production but instead the movement of money(value) from one virtual account to another.

A skilled tradesman can get work after vocational high school or a two year vocational program and have a head start on the college students.
  Initial earnings will often be greater than the college grads for a number of years but tends to slow down and cap earlier and lower than the degree holders.

All that said, some college grads do walk into high pay right out of college and some college dropouts make it rich.
Some high school dropouts make it rich.

But here is a fact for you: the trades are more secure employment, as long as you are willing to WORK and can meet basic competency levels.

If you don't want to work or are not competent - just go get an MBA.

Comment Google continues down their path (Score 2) 92

Google started out providing users a service they wanted:
Fast, accurate search results without a lot of garbage
- Since then they have "improved" Google search to the point of being comparable to Bing - ie.: not very good

Fast, easy to use webmail
-since then they have improved it to the point of being crappy but usable on a computer but basically irrelevant on a cellphone screen. Outlook Mobile is better than the Gmail app.

Google Maps was something of a revelation when introduced
- since then they have filled it with so much garbage and now a horrible UI color scheme that it is next to unusable.

Google seems to be on a path to self destruction.

There will be others who pick up the slack as Google fails.

Slashdot Top Deals

OS/2 must die!

Working...