100
Concerning CrowdStrike (infosec.exchange)
submitted 2 months ago by uis@lemm.ee to c/linuxmemes@lemmy.world

We are now at t+26h. Please compare how much we knew about the xz-attack after less than a day with what we know about the chain of events of giant outage yesterday.

If something similar had been caused by an OSS component, we would see congress discussing a ban on open software in critical infrastructure already.

top 8 comments
sorted by: hot top controversial new old
[-] slazer2au@lemmy.world 129 points 2 months ago

If something similar had been caused by an OSS component, we would see congress discussing a ban on open software in critical infrastructure already.

No we won't. I refer to HeartBleed, Log4J, and Eternal Blue, and Solar winds. None of those affected applications have been banned and never will. Congress bans are based on political aspects not technical ones.

Huawei ban is because of the ties to China, kaspersky was banned because of Russian ties.

[-] Artyom@lemm.ee 24 points 2 months ago

Security vulnerabilities are a big deal in the tech world, but no one really cares outside of that. The CrowdStrike bug was big because it was user-facing and shut down systems. The truth is we haven't seen any user-facing bugs from open source software to compare CrowdStrike to.

[-] ProjectPatatoe@lemmy.world 1 points 2 months ago

But... if I don't propose a ban, everyone will think I don't know what i'm doing

[-] OpenStars@discuss.online 12 points 2 months ago

The goal of Congress in a capitalist society is to make as much money for ~~its shareholders~~ themselves as possible.

img

When you vote for this, you get this, plain and simple.

People are shocked, Shocked I tell you, SHOCKED to learn this... but what else would you expect?

this post was submitted on 20 Jul 2024
100 points (82.5% liked)

linuxmemes

21009 readers
397 users here now

Hint: :q!


Sister communities:


Community rules (click to expand)

1. Follow the site-wide rules

2. Be civil
  • Understand the difference between a joke and an insult.
  • Do not harrass or attack members of the community for any reason.
  • Leave remarks of "peasantry" to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
  • Bigotry will not be tolerated.
  • These rules are somewhat loosened when the subject is a public figure. Still, do not attack their person or incite harrassment.
  • 3. Post Linux-related content
  • Including Unix and BSD.
  • Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of sudo in Windows.
  • No porn. Even if you watch it on a Linux machine.
  • 4. No recent reposts
  • Everybody uses Arch btw, can't quit Vim, and wants to interject for a moment. You can stop now.

  • Please report posts and comments that break these rules!

    founded 1 year ago
    MODERATORS