pwshub.com

Congress grills CrowdStrike about multibillion-dollar July outage

Members of Congress grilled a senior executive of security company CrowdStrike on Tuesday, demanding to know why it triggered a cascading, multibillion-dollar tech failure in July that shut down 911 call centers, handicapped hospitals and stranded airplane passengers around the world.

House Homeland Security Committee Chairman Mark Green (R-Tenn.) faulted chief executive George Kurtz for ducking his request to testify and sending a threat intelligence expert instead to face questioning on one of the most catastrophic failures in tech history.

“Everywhere Americans turned, basic societal functions were unavailable,” Green said. “We cannot allow a mistake of this magnitude to happen again.”

CrowdStrike senior vice president Adam Meyers apologized for the disaster, echoing previous statements by Kurtz and laying out the technical missteps that allowed a faulty configuration update to balloon into a “Blue Screen of Death” on more than 8 million Windows devices running CrowdStrike’s antivirus sensors. For the first day, rebooting worked only if someone talked each user through a process specific to their machine.

Meyers’s account before the House committee, like a deeper analysis that CrowdStrike has published, accepted responsibility for the outage but couched it as a consequence of the market-leading company’s quest for efficiency in responding quickly to new threats.

More than a dozen former employees, however, recently told web publication Semafor that the company prioritized speed over quality, recounting multiple instances when they had sought to review and improve code before shipping it, only to be rebuffed.

CrowdStrike told the publication that it was practical to deploy programs and then make them better. The company didn’t immediately respond to a request for comment from The Washington Post.

But after the July 19 collapse, the company acknowledged having violated well-established best practices, including testing changes on a wide array of devices and distributing them to a small group of customers before sending them everywhere. Meyers told lawmakers on Tuesday that those patterns had been corrected.

A key reason that the impact was so great is that CrowdStrike’s programs occupy a privileged position inside computers, with access to the Windows kernel that controls nearly all levels of the device. That access is standard for scores of security programs, because they need to be up and running quickly, before viruses or hackers can get deep into the device and shut down the security protections.

Some efforts are underway to find security approaches that entail less systemic vulnerability. Earlier this month Microsoft convened a meeting of software architects, security companies and regulators at its campus and recently said it would develop an alternative to kernel access that offers much of the same functionality. Parts of a test version could be ready in as little as six months, David Weston, Microsoft’s vice president for operating system security, told The Post.

While there are no plans yet to force security vendors to such an alternative, Weston said any new rules would apply equally to Microsoft’s own security offerings. He said Microsoft would also require better testing regimens for those relying on kernel access.

In the meantime, the estimated $5.4 billion failure has cost high-flying CrowdStrike tens of millions of dollars in revenue and billions in stock market value. Hard-hit Delta Air Lines, which canceled thousands of flights and is being sued by its travelers, has threatened to sue CrowdStrike for $5o0 million.

Kurtz said CrowdStrike was legally responsible for less than $10 million of those damages. He and Microsoft said Delta’s poor practices left it in much worse shape for longer than other airline customers.

The outage underscored the deep interdependence of computer-based systems, driving home widespread fears about the adequacy of efforts to limit the impact of a deliberate attack by a foreign government.

It has also given new impetus to efforts to devise a way to hold software providers legally liable for gross negligence. They are now broadly exempt.

Jen Easterly, director of the Cybersecurity and Infrastructure Security Agency, said in an interview that she has been speaking to members of the Homeland Security Committee and others about a plan that would permit such lawsuits, supplemented by significant “safe harbor” provisions that would exempt companies following good practices.

Source: washingtonpost.com

Related stories
5 hours ago - Argues worse could happen if it loses kernel access CrowdStrike is "deeply sorry" for the "perfect storm of issues" that saw its faulty software update crash millions of Windows machines, leading to the grounding of thousands of planes,...
1 month ago - The Affordable Connectivity Program expired in May, leaving 23 million low-income households with higher internet bills.
6 days ago - Patently retro — PERA and PREVAIL want to re-enable patents struck down by Supreme Court rulings. ...
1 month ago - Bipartisan pressure in Congress emerges for OpenAI to prove it is developing its AI safely.
1 month ago - Earlier this year, deepfake pornography depicting Taylor Swift spread online, causing significant backlash. This incident seemed to be a tipping point for regulators, with members of Congress and even the White House weighing in on the...
Other stories
2 hours ago - Service due to roll out later this month, despite fears AI will crash the market AI has driven the stock market into a hype-fueled frenzy, and an Israeli startup has even convinced regulators to let its chatbot hallucinate an investment...
2 hours ago - Here's today's Connections answer and hints for groups. These clues will help you solve New York Times' popular puzzle game, Connections, every day!
2 hours ago - Here's today's Wordle answer, plus a look at spoiler-free hints and past solutions. These clues will help you solve New York Times' popular puzzle game, Wordle, every day!
2 hours ago - There are many affordable alternatives to the Peloton bike in the market. We've tested quite a few, and here are the ones we think are the best.
4 hours ago - Open-World Action Games — The follow-up to one of our favorite open-world games is coming soon, Sony says. ...