X

Vous n'êtes pas connecté

Rubriques :

Maroc Maroc - NEWSDAY.CO.TT - A la Une - 05/Aug 08:22

The consequences of code

BitDepth#1470 Mark Lyndersay ON JULY 19, cybersecurity firm Crowdstrike sent an automatic update to Microsoft Windows computers that was intended to upgrade the Falcon sensor security solution it sells to enterprise. The worst possible thing happened. A bug in the code sent the computers that received into a death spiral of blue screens. The update was just 40 kilobytes in size and was intended to adjust the sensor's ability to detect malware. Instead, it caused more than US$6 billion in real world damage. Delta Airlines alone, which deployed the software widely in its computer network, reported losses of more than US$500 million over the week it struggled to normalise operations after the Crowdstrike bug crippled the company's ability to function. Microsoft estimates that more than eight million Windows computers were affected by the bug. Crowdstrike quickly deployed a patch that corrected the issue, but for many customers, it fixed nothing. Falcon is an endpoint sensor widely used in computers that run systems like automated kiosks and customer interface panels that were also secured by Microsoft's BitLocker encryption software. On those computers, it was necessary to decrypt the hardware, apply the patch then restart. Roughly 20 minutes work, multiplied by hundreds of devices. Delta's long path to restoring operations was apparently compounded by outsourced IT, which meant fewer people available to "touch" stricken computers. TT was largely unscathed by the incident (https://cstu.io/36e5d9), and most organisations affected by the bug reported resumption of transactions within 24 hours. "Do I think that TT dodged a bullet because Crowdstrike is expensive? Yes," said cybersecurity specialist Shiva Parasram. "The fact that Crowdstrike is very popular but very expensive might be one of the factors limiting its impact in Trinidad. "But it's not necessarily a good thing. The reason why there was minimal impact is because we don't really spend much on cybersecurity." The cruel reality of Crowdstrike is that it wasn't a cybersecurity attack. It was a quality of service lapse and the incident puts IT professionals in an odd space, sandwiched between determined and sustained attacks by hackers and ransomware organisations and hastily deployed software that ends up fragging their systems from the inside. Do IT pros do all recommended updates as they are issued and risk buggy updates like Crowdstrike? Do they wait a few days and risk compromise because of outdated security measures or unplugged security holes? Do they create a sandboxed update system to confirm that updates are safe? If so, how practical would that be for typically underpaid, overworked local IT teams? Parasram believes that sandboxed test systems to confirm updates are something that companies will have to build into their IT management. "It's not going to get any easier for TT," he said. "But we have a lot more graduates coming out, new professionals who are looking for a start. Companies will have to get serious about disaster recovery and that includes cloud service providers and software as a service. "Companies have to do third-party risk assessments on these businesses, ensure that they are certified, that they have qualified teams, that they are on the ground. What is their response time (when disaster strikes)? "People don't take on service-level agreements, but you have to look at how much downtime and uptime are guaranteed and if it's not provided, you are due compensation. Service-level agreements and contracts have to be studied quite carefully to ensure that these critical services are supplied." As the immediacy of Crowdstrike disruptions gave way to analysis of the incident, talk of legal liability began to surface. What should TT take away from the Crowdstrike bug? Top of the list is that businesses and government agencies are responsible for the sanctity of their computer systems and every business decision should be predicated on maximising cybersecurity. Contingency planning must be thorough, exhaustive and well-exercised. When systems fail, customers and the public don't actually care and often don't understand distributed responsibilities, so blaming other companies and services is always going to fall flat. While TT customers have a high tolerance for service abuse, they should not be expected to offer eternal grace for digital failures. TSTT weathered the humiliation of having private customer information exposed on the dark web and later the open internet by offering its CEO and CFO as public sacrifice. iGovTT managed to dodge public opprobrium after its proud achievement, TTConnect, simply disappeared for months. With no legal requirement to notify anyone of cybersecurity breaches, other exposures of personally identifiable information remain largely unknown. What we don't know can, in fact, hurt us. Mark Lyndersay is the editor of technewstt.com. An expanded version of this column can be found there The post The consequences of code appeared first on Trinidad and Tobago Newsday.

Articles similaires

Chambers, cops advise small businesses: Don’t pay extortionists

newsday.co.tt - 30/Aug 04:46

President of the Tunapuna Police Station Community Council and director of the Greater Tunapuna Chamber of Industry & Commerce Neil Boodoosingh says...

Senator Maharaj: People losing hope for change

newsday.co.tt - 07/Sep 16:24

FORMER journalist and Independent Senator Sunity Maharaj says constitutional reform is the beginning of a means to begin to anchor a culture of...

Sorry! Image not available at this time

One More Tool Will Do It? Reflecting on the CrowdStrike Fallout

itsecuritynews.info - 09/Sep 14:32

The proliferation of cybersecurity tools has created an illusion of security. Organizations often believe that by deploying a firewall, antivirus...

Sorry! Image not available at this time

One More Tool Will Do It? Reflecting on the CrowdStrike Fallout

itsecuritynews.info - 09/Sep 14:32

The proliferation of cybersecurity tools has created an illusion of security. Organizations often believe that by deploying a firewall, antivirus...

MP Hosein: Blame PM for crime

newsday.co.tt - 02/Sep 11:53

SADDAM Hosein, MP for Barataria/San Juan, rejected the Prime Minister’s recent disavowal of any blame for the spike in violent crime, speaking at a...

MP Hosein: Blame PM for crime

newsday.co.tt - 02/Sep 11:53

SADDAM Hosein, MP for Barataria/San Juan, rejected the Prime Minister’s recent disavowal of any blame for the spike in violent crime, speaking at a...

Trinidad and Tobago Scouts move camp to Guyana

newsday.co.tt - 28/Aug 07:56

This year, for the first time, the Scout Association of Trinidad and Tobago moved its annual national camp out of the country, taking 21 scouts to...

What’s in store for Store Bay?

newsday.co.tt - 09/Sep 07:44

THE question on everyone’s lips is what’s in store for one of the most beautiful beaches in Tobago. The Tobago House of Assembly intends to turn...

SKMM / MCMC Share More Regarding DNS Redirection Implementation

thecekodok.com - 07/Sep 20:14

One of the things that became a hot conversation for a day or two was related to the implementation of DNS redirection by internet service providers...

Windows Recall Can't Be Removed By User

thecekodok.com - 03/Sep 13:50

The WIndows Recall feature will be given to Windows Insider users for a second phase of testing next October. The original plan to offer it to all...

Les derniers communiqués

  • Aucun élément