All of this has happened before, and it will all happen again ...

Jul 19, 2024 8:03 PM

inkican

Views

13276

Likes

601

Dislikes

5

https://www.zdnet.com/article/defective-mcafee-update-causes-worldwide-meltdown-of-xp-pcs/

MV Edit - Yeah, you can't make this stuff up. May I offer you a made-up story in these trying times?
https://inkican.com/hot-scifi-summer-short-stories-free-smashwords/

The more things change the more they remain the same

2 years ago | Likes 1 Dislikes 0

well, well, well. I wonder what kind of best practices he brought along to the new company.

2 years ago | Likes 1 Dislikes 0

Was this before or after hulk Hogan

2 years ago | Likes 1 Dislikes 0

2 years ago | Likes 2 Dislikes 0

"What if we did A/B testing?" "Nah, that takes time and effort, ship it"

2 years ago | Likes 2 Dislikes 0

George is an agent of chaos.

2 years ago | Likes 2 Dislikes 1

Failing upwards. Or... Laterally I guess?

2 years ago | Likes 1 Dislikes 0

Ain’t his first rodeo , granted he lost both rodeos

2 years ago | Likes 1 Dislikes 0

Is that title part of the opening voice over at the beginning of Armageddon (1998)?

2 years ago | Likes 1 Dislikes 0

Always hire the best. But, if you can't afford that…..

2 years ago | Likes 1 Dislikes 0

Is he shorting tech stocks? Nice retirement plan.

2 years ago | Likes 7 Dislikes 0

At a certain point, some people only fail upwards. #3 Enron exec at time of collapse now runs SkyWest airlines. Bowing CEO got a $30m golden parachute (ironic). Drumpf is running for president, again. We designed civilization wrong.

2 years ago | Likes 2 Dislikes 0

You spelled capitalism wrong!

2 years ago | Likes 2 Dislikes 0

Is hard for an old dog to change his stripes

2 years ago | Likes 9 Dislikes 0

"Waste makes haste, for time is fleeting. A rolling stone is worth two in the bush."

2 years ago | Likes 2 Dislikes 0

*McAfee

2 years ago | Likes 30 Dislikes 0

Ha, I was saying to my partner left night how can this happen given it's happened before and updates you would therefore expect to be checked, checked and checked again for this very reason.

2 years ago | Likes 5 Dislikes 0

My question is, asking as a layman, do they not test these updates internally before pushing them out?

2 years ago | Likes 1 Dislikes 0

That would be my hope

2 years ago | Likes 2 Dislikes 0

I read this as McCafé and was like "yeah I can see a faulty McDonalds machine causing this."

2 years ago | Likes 3 Dislikes 0

Explains why the icecream mashine is always broken

2 years ago | Likes 3 Dislikes 0

He has a degree in accounting

2 years ago | Likes 3 Dislikes 0

Then let’s hold him accountable.

2 years ago | Likes 3 Dislikes 0

2 years ago | Likes 22 Dislikes 0

Umm... what lesson would that be? That we'll take it and pretend to like it?

2 years ago | Likes 1 Dislikes 0

Whats John Mcafee up to these days?

2 years ago | Likes 3 Dislikes 0

2 years ago | Likes 3 Dislikes 0

He's dead

2 years ago | Likes 5 Dislikes 0

Whale, I'm not sure, but probably something illegal. I mean, assuming he faked his death.

2 years ago | Likes 4 Dislikes 0

Is nice knowing that we are hanging by one bad Update from thousands of companies

2 years ago | Likes 61 Dislikes 0

And not even 1 update - many affected customers weren't on latest patch level (n-1 and n-2 were also affected).

2 years ago | Likes 1 Dislikes 0

Everyone is just one bad day from going insane.......

2 years ago | Likes 11 Dislikes 0

2 years ago | Likes 2 Dislikes 0

...or one intentional update from someone with bad intent. https://www.imdb.com/title/tt0113957

2 years ago | Likes 2 Dislikes 0

Why bother to hack when all you need to do to hold them hostage is... one bad update file?

2 years ago | Likes 1 Dislikes 0

A few months ago somebody managed to slip malware into a nightly build of Red Hat. They caught it after a few weeks and it would have been years before that build would have gotten to a stable release; but that's the real danger, particularly with LLMs being used by coders. I am sure that state-sponsored hackers are working on ways to get ChatGPT to produce code that introduces vulnerabilities, so when people use the code they open the door for the hackers.

2 years ago | Likes 8 Dislikes 1

Several years ago it was found that a CIA .dll made it into Notepad++ which let it kick off other code under the surface. I can promise you that kind of work is ongoing.

2 years ago | Likes 4 Dislikes 0

3 years ago the same thing happened with the linux kernel itself, in the name of science

https://www.theverge.com/2021/4/30/22410164/linux-kernel-university-of-minnesota-banned-open-source

2 years ago | Likes 2 Dislikes 0

Why does this one line dump the database and send it to 中共中央办公厅 ?

2 years ago | Likes 5 Dislikes 0

> somebody managed to slip malware into a nightly build of Red Hat

That's not at all an accurate summation of the situation.

2 years ago | Likes 1 Dislikes 2

lol Downvoters downvoting facts.

2 years ago | Likes 1 Dislikes 0

Quote: We have determined that Fedora Linux 40 beta does contain two affected versions of xz libraries - xz-libs-5.6.0-1.fc40.x86_64.rpm and xz-libs-5.6.0-2.fc40.x86_64.rpm. At this time, Fedora 40 Linux does not appear to be affected by the actual malware exploit, but we encourage all Fedora 40 Linux beta users to revert to 5.4.x versions.

2 years ago | Likes 2 Dislikes 1

That's an accurate description of the end result. The backdoor wasn't "slipped in". It required years of effort on the part of the bad actor(s), and a chain of unlikely situations to align in just the right way.

2 years ago | Likes 1 Dislikes 1

Any app can have a bad update. in 2010 most of us were running Win 7 so we could still just press F8 to choose safe mode. Getting into Windows 10 safe mode when you need to... sometimes requires effort. Microsoft holds a large share of the blame for today's fiasco, because the recovery tools in Windows 10/11 are more difficult to use.

2 years ago | Likes 179 Dislikes 9

The details of this bad update though...it was clearly 100% untested, no QA, no review, nothing. It indicts Crowdstrikes entire system. Crashes in corner cases with unusual hardware and configurations are inevitable. Crashes with literally all systems? That's colossal and shouldn't ever happen.

2 years ago | Likes 3 Dislikes 0

Fuck you CrowdStrike! I want restitución! Thank you MSFT for helping mitigate!

2 years ago | Likes 5 Dislikes 0

We had so much fun working with a few dozen remote users whose machines REFUSED to even enter Recovery mode. Really that was more annoying than even Bitlocker or guiding through CLI

2 years ago | Likes 2 Dislikes 0

I'm a former IT guy that was embarrassed to admit today I didn't know the shortcut for safe mode. Turns out there isn't one? Neat.

2 years ago | Likes 11 Dislikes 0

ESPECIALLY IF THEY ARE LOCKED BEHIND BITLOCKER…anyone else, or was it just me with that insult added to injury?

2 years ago | Likes 6 Dislikes 0

I just googled. BIG OOF. they published a fix but it isn't exactly click click done... https://www.crowdstrike.com/wp-content/uploads/2024/07/BitLocker-recovery-in-Microsoft-environments-using-Active-Directory-and-GPOs.pdf

2 years ago | Likes 5 Dislikes 0

And because we don't get to choose to update. Updates are rammed down everyone's throats simultaneously.

2 years ago | Likes 64 Dislikes 10

My SO was giving birth a few days ago and the laptop attached to the ECG (and all other computers in the room) had to reboot within the same hour. Windows, of course. No option to delay the upgrade.

2 years ago | Likes 1 Dislikes 1

Absolute nonsense, as usual; the fact you're unaware of this is precisely the reason the default configuration is the way it is and you're the intended class of user. Working as intended.

2 years ago | Likes 10 Dislikes 5

This wasn't a Windows Update, it was from Crowdstrike and only workstations running Crowdstrike were affected.

2 years ago | Likes 23 Dislikes 2

Not 100% true in Domains where WSUS is configured and used. I control the approval of what gets to my users, and when.

2 years ago | Likes 28 Dislikes 0

Would you care to enroll some of my end users in your AD forest? :D

2 years ago | Likes 9 Dislikes 1

wait....F8 doesn't work anymore?

2 years ago | Likes 19 Dislikes 0

Nope, in a stroke of genius on Microsoft's part, they made it so that you have to successfully boot into Windows in order to reboot into safe mode.

2 years ago | Likes 23 Dislikes 5

That's so stupid it sounds made up lol

2 years ago | Likes 22 Dislikes 0

Because it is made up. If your PC fails to load Windows 3 times in a row, the next attempt will boot directly into the Recovery menu where you can access a number of recovery options, including Safe Mode.

2 years ago | Likes 20 Dislikes 3

Some models can. As I discovered today, some of the newer model laptops I worked with do not have those particular startup options from recovery. Fast irony that safe mode has never been useful to me until today, and it's when it mattered most, when its getting removed as a feature.

2 years ago | Likes 1 Dislikes 0

Only if it gets to that trigger point. Otherwise you sit in an endless reboot cycle until you boot from another disk.

2 years ago | Likes 8 Dislikes 1

My failed yesterday. But looks like it was a coincidence. I have b550 f gaming mobo. No safe mode so I had to get in bios page. Idk much so I didn't change anything and just rebooted. From black screen now I at least to an image with asus logo. From there somehow I got the option to choose where to boot windows and finally windows started when I selected my ssd. Didn't reboot again so not sure if it still works.

2 years ago | Likes 2 Dislikes 0

That sounds like a straight downgrade tbh.

2 years ago | Likes 7 Dislikes 0

I should be able to go directly to safe mode from a cold boot if I feel like it.

2 years ago | Likes 17 Dislikes 0

Big if true. This assumes windows recognizes it has failed to boot, or gets to a point where it officially fails to boot.

2 years ago | Likes 6 Dislikes 0

Hahaha, has that actually worked for you? If normal booting fails and I get the recovery menu, selecting safe mode will reset the computer and bring me back to the recovery menu. Happened four times in five years with my old 2013 miniPC as well as last weekend with my nine month-old 5950X desktop.

2 years ago | Likes 3 Dislikes 1

Only if that menu is working, man the amount of trouble I have had with that menu... Just let me boot directly into safe mode.

2 years ago | Likes 2 Dislikes 0