Last Friday, a major CrowdStrike outage impacted PCs running Microsoft Windows, causing worldwide issues affecting airlines, retailers, banks, hospitals, rail networks, and more. Computers were stuck in continuous recovery loops,
Last Friday, a major CrowdStrike outage impacted PCs running Microsoft Windows, causing worldwide issues affecting airlines, retailers, banks, hospitals, rail networks, and more. Computers were stuck in continuous recovery loops, rendering them unusable.


The failure was caused by an update to the CrowdStrike Falcon antivirus software that auto-installed on Windows 10 PCs, but Mac and Linux machines were not affected even though they received the same software. A report from The Wall Street Journal delves into what happened and includes some critical information from Microsoft on why Macs did not get taken out by the update.

On Windows machines, CrowdStrike's Falcon security software is a kernel module, which gives the software full access to a PC. The kernel manages memory, processes, files, and devices, and it's basically the heart of the operating system. Much of the software on a PC is typically limited to user mode, where bad code can't cause harm, but software with kernel mode access can cause catastrophic total machine failures, like what was encountered last week.

The Falcon software was not able to wreak similar havoc on Macs because Apple does not give software makers kernel access. In macOS Catalina, which came out in 2019, Apple deprecated kernel extensions and transitioned to system extensions that run in a user space instead of at a kernel level. The change made Macs more stable and more secure, adding protection against unstable software updates like the one CrowdStrike pushed out. It is not possible for Macs to have a similar failure because of the change that Apple made.

In a statement to The Wall Street Journal, Microsoft blamed the European Commission for an inability to offer the same protections that Macs have. Microsoft said that it is unable to wall off its operating system because of an "understanding" with the European Commission. Back in 2009, Microsoft agreed to interoperability rules that provide third-party security apps with the same level of access to Windows that Microsoft gets. Microsoft agreed to provide kernel access in order to resolve multiple longstanding competition law issues in Europe.

Apple has not been forced to make changes to how Macs work, but the European Commission has been targeting the closed nature of iOS, and Apple has warned that the updates that have already been implemented could lead to security risks in the future. The European Union's Digital Markets Act has pushed Apple to allow developers to offer apps through third-party marketplaces and websites. Apple says explicitly that the DMA compromises its ability to "detect, prevent, and take action against malicious apps."

The major CrowdStrike failure that affected Windows PCs highlights some of the unintended consequences and the tradeoffs inherent in legislation that weakens security in the name of open access. CrowdStrike's simple software update impacted global infrastructure, bringing travel, commerce, and healthcare to a standstill.

Microsoft does not seem to have a way to stop a recurrence because it can't cut off kernel access. The company says that significant incidents "are infrequent" and that less than one percent of all Windows machines were impacted. CrowdStrike says that it is "deeply sorry for the inconvenience and disruption," and that in the future, it will share the steps that it is taking to prevent a similar situation.
This article, "Microsoft Blames European Commission for Major Worldwide Outage" first appeared on MacRumors.com

Discuss this article in our forums

original link


You may also be interested in this

The History of the Apple …

In the mid-1980s, Apple Computer was riding high on the success of its revolutionary products, but turbulent times were ahead. This period, spanning from 1985 to 1997, marked a crucial

Apple readies generative …

Apple, scrambling to catch up in artificial intelligence capabilities, is nearing the completion of a generative AI tool for app developers that would step up competition with the world’s most

Samsung abandons plans to…

Samsung has decided to stop its internal assessment that explored the possibility of switching the default search engine on its smartphones to Microsoft's Bing.Samsung continues with GoogleOpenAI's technology has been

Immerse yourself in hundr…

StackSkills Unlimited offers courses in IT, web design, coding, Adobe Creative Cloud, Microsoft Office, marketing and even foreign languages. (via Cult of Mac - Tech and culture through an Apple

Apple Reality Pro MR head…

Macworld It’s looking more and more like Apple’s next big thing won’t be something that fits in your pocket or a bag. Rather it could be another wearable device–specifically an

What is a smart home, and…

Illustration by Samar Haddad for The Verge As connected becomes the default for every household appliance — from TVs and washing machines to ovens and vacuums — we break down

Google CEO ‘Lord Fa…

It's been a tough year for tech, but even as Google laid off 12,000 employees, CEO Sundar Pichai got a substantial pay raise, earning him the nickname "Lord Farquaad."Google CEO

Saskatchewan tech compani…

Google, Amazon, Microsoft, Meta, Twitter, Spotify and more big tech companies have all been making major cuts to its workforce. Saskatchewan, however, has been growing.
X

A whimsical homage to the days in black and white, celebrating the magic of Mac OS. Dress up your blog with retro, chunky-grade pixellated graphics to evoke some serious computer nostalgia. Supports a custom menu, custom header image, custom background, two footer widget areas, and a full-width page template. I updated Stuart Brown's 2011 masterpiece to meet the needs of the times, made it responsive , got dark mode, custom search widget and more.You can download it from tigaman.com, where you can also find more useful code snippets and plugins to get even more out of wordpress.