IT End of World - S...
 

IT End of World - STW going strong

146 Posts
79 Users
22 Reactions
1,745 Views
Posts: 9130
Full Member
Topic starter
 

Flights grounded, trains halted, stock exchange not trading, Sky news off air. But the (previously) flakiest forum in the world just powers on without issue.

Will be soon be running the world through STW?

 
Posted : 19/07/2024 9:20 am
Posts: 11379
Free Member
 

For the first time ever it’s a good job this place runs on analogue hamsters.

 
Posted : 19/07/2024 9:29 am
Posts: 6581
Free Member
 

Going strong? We can't even use emojis

 
Posted : 19/07/2024 9:30 am
Posts: 5656
Free Member
 

Our work systems are still going...... bugger

 
Posted : 19/07/2024 9:31 am
Posts: 11379
Free Member
 

But look what’s happening to websites that can

 
Posted : 19/07/2024 9:31 am
Posts: 3954
Full Member
 

I wish Teams was down, would get me out of a number of meetings this morning that I really can't be arsed with!

I hope I don't regret my flippancy when battling to survive after the Great Crash

 
Posted : 19/07/2024 9:33 am
Posts: 6653
Full Member
 

Flights grounded,
Trains halted,
Stock exchange not trading,
Sky news off air.
Paxman and his underwear

You'll be telling us you started a fire next...

 
Posted : 19/07/2024 9:34 am
 PJay
Posts: 4693
Free Member
 

Link here - https://www.bbc.co.uk/news/live/cnk4jdwp49et

 
Posted : 19/07/2024 9:34 am
Posts: 2175
Free Member
 

RIP to the person that rolled that update out last night...

 
Posted : 19/07/2024 9:35 am
Posts: 13388
Full Member
 

I blame Starmer!!!

Two weeks of Labour and look and what happens! 🙂

 
Posted : 19/07/2024 9:36 am
Posts: 7536
Full Member
 

RIP to the person that rolled that update out last night…

Its only a quick update to the DNS servers what can go wrong?

 
Posted : 19/07/2024 9:36 am
Posts: 1252
Free Member
 

It's been caused by Crowdstrike, the fix requires booting each system that is having problems to safe mode. Bit of a nightmare weekend ahead if you are a Crowdstrike user.

 
Posted : 19/07/2024 9:37 am
Posts: 10671
Full Member
 

the fix requires booting each system that is having problems to safe mode

So when Microsoft say they are taking "mitigating action" they actually do mean turning it off and back on again?

 
Posted : 19/07/2024 9:39 am
 timf
Posts: 137
Free Member
 

I can not re boot my work pc to safe mode because I do  not have my bitlocker encryption key   I might have noted it somewhere safe when I last reimaged my work pc  4 years ago,  but no recall where that might be.

With hindsight pity  I have not re-imaged to windows 11 as our compay help portal is saying a re boot resolved issue on windows 11.

 
Posted : 19/07/2024 9:44 am
Posts: 1252
Free Member
 

So when Microsoft say they are taking “mitigating action” they actually do mean turning it off and back on again?

It's not something Microsoft can fix with a restart, more details below.

https://twitter.com/SimoKohonen/status/1814188665012158914

 
Posted : 19/07/2024 9:47 am
 pk13
Posts: 2723
Full Member
 

It's a big un the IT bods at my work have put on their panic Crocs.

 
Posted : 19/07/2024 9:47 am
Posts: 4607
Free Member
 

Sports mode or regular mode?

 
Posted : 19/07/2024 9:52 am
Posts: 354
Free Member
 

Hmm I wonder if I can make any Cisco Secure Endpoint sales today

 
Posted : 19/07/2024 9:53 am
Posts: 11379
Free Member
 

IT people stressing out on one of the hottest days of the year so far? Urgh think of the stench.

 
Posted : 19/07/2024 9:54 am
Posts: 1653
Free Member
 

@bassmandan

funnily ive just put crowdstrike on my blacklist

and we have recently started running with cisco secure kit 😀

 
Posted : 19/07/2024 9:56 am
Posts: 920
Free Member
 

Cracking comment on The Register :

"The major difference between a thing that might go wrong and a thing that cannot possibly go wrong is that when a thing that cannot possibly go wrong goes wrong it usually turns out to be impossible to get at and repair."

- Douglas Adams

How true this is for the Cloud. The man was totally ahead if his time.

 
Posted : 19/07/2024 10:02 am
Posts: 6183
Full Member
 

I wish Teams was down

I wish Teams was down permanently

 
Posted : 19/07/2024 10:03 am
Posts: 2434
Free Member
 

My work lap won’t boot, BSOD.

Just imagine being the PM responsible for this update though. Wow!

This is going to cost a lot of money in lost productivity.

 
Posted : 19/07/2024 10:04 am
 IHN
Posts: 19468
Full Member
 

IT people stressing out on one of the hottest days of the year so far? Urgh think of the stench.

All my stuff's working fine thanks *smugface

 
Posted : 19/07/2024 10:07 am
Posts: 6866
Full Member
 

Curious. I had to reboot once at home 10 hours ago. A colleague said it took much longer. But everything else was fine all day.

 
Posted : 19/07/2024 10:10 am
Posts: 3489
Free Member
 

All my stuff’s working fine thanks *smugface

Well you've jinxed it now

 
Posted : 19/07/2024 10:20 am
Posts: 2335
Free Member
 

Damn we've just run out of TEA! I was going shopping ?

 
Posted : 19/07/2024 10:22 am
Posts: 460
Free Member
 

I'm finding it amusing that the train companies have seen what's going on and have announced that 'trains are delayed'.

 
Posted : 19/07/2024 10:23 am
 jimw
Posts: 3243
Free Member
 

I can’t log onto EMIS, so it looks like it is is going to be a bad day for many patients doctors and admin staff in GP practices this morning. The NHS app will also have limited access to patient data

 
Posted : 19/07/2024 10:25 am
Posts: 7039
Free Member
 

My work Linux PC seems fine, as does my work Linux laptop.

 
Posted : 19/07/2024 10:26 am
Posts: 6529
Full Member
 

Oddly enough I'm running a Cloud project...I'll get my coat.

 
Posted : 19/07/2024 10:28 am
 timf
Posts: 137
Free Member
 

Have got my bit locker recovery key from my online Microsoft account

 
Posted : 19/07/2024 10:30 am
Posts: 7039
Free Member
 

https://en.m.wikipedia.org/wiki/CrowdStrike

Wikipedia article updated!

On the 19th July 2024, a Crowdstrike update crashed millions of computers worldwide and allowed AI to take over the world and get rid of snowflakery and wokerism!

 
Posted : 19/07/2024 10:35 am
Posts: 8391
Full Member
 

Ooh, it’s bin day. Do you think they’ll still be emptied?

 
Posted : 19/07/2024 10:37 am
Posts: 13388
Full Member
 

Damn we’ve just run out of TEA! I was going shopping ?

M&S Foodstore in Matlock is operating just fine - so maybe try M&S! 🙂

Local newsagents till also working fine - bought my Euromillions and Private Eye this morning.

 
Posted : 19/07/2024 10:37 am
Posts: 15778
Free Member
 

Why close the thread with the obvious title and keep the one with the obscure title which will create more threads ?‍♂️

 
Posted : 19/07/2024 10:40 am
Posts: 3572
Free Member
 

To the less IT literate Crowdstrike sounds like malware. It does to me anyway.

 
Posted : 19/07/2024 10:41 am
Posts: 2335
Free Member
 

Nearest M&S is an hour away! Will find out soon enough when I go to Asda or Tesco.

We do have coffee and tap water so won't die, but TEA!

 
Posted : 19/07/2024 10:43 am
 timf
Posts: 137
Free Member
 

Have used the above fix of deleting the file from the croudstrike directory and my pc has rebooted.

 
Posted : 19/07/2024 10:49 am
Posts: 13388
Full Member
 

Nearest M&S is an hour away!

No M&S Foodstore - your area must be proper poor!!! 🙂

 
Posted : 19/07/2024 10:50 am
Posts: 8487
Full Member
 

What actually is Cloudstrike?

 
Posted : 19/07/2024 10:52 am
Posts: 5389
Full Member
 

Hope no-one has shares in Crowdstrike

 
Posted : 19/07/2024 10:52 am
Posts: 9421
Free Member
 

On Monday I'll be walking into my workroom and making curtains as usual.

Hoorah for STW, however the 'like' button still doesn't work.

 
Posted : 19/07/2024 10:54 am
milan b. and milan b. reacted
Posts: 76786
Free Member
 

https://twitter.com/FFF182/status/1814215680553894054

 
Posted : 19/07/2024 10:57 am
Posts: 4130
Free Member
 

OK... Did anyone else (apart from me and the 20+ other blokes here in work) see Sky News boardcasting Pro Russian news on loop between 0630 and 0745...

(No! !.... None of us are wearing foil hats)

 
Posted : 19/07/2024 10:59 am
Posts: 3383
Free Member
 

To the less IT literate Crowdstrike sounds like malware. It does to me anyway.

I am IT literate, and it sounds like that to me too 🙂

What actually is Cloudstrike?

Rather ironically, it's a system intended to stop hackers crashing PCs 😀

 
Posted : 19/07/2024 10:59 am
Posts: 90742
Free Member
 

How true this is for the Cloud.

It's true for everything not just IT. A large part of my job is telling people that yes, this COULD go wrong and if it does it will cost you a lot of money, so mitigate it.

My work is unaffected but I have not been able to get onto STW all morning until now.

 
Posted : 19/07/2024 11:21 am
 DT78
Posts: 10061
Free Member
 

Its crazy there aren't enough fail safes built in to the system to prevent one component having a wobbly bricking things that integrate with it.

Reminds me of the air traffic control system says no moment a few years ago, but way worse....

 
Posted : 19/07/2024 11:22 am
Posts: 8552
Full Member
 

There will definitely be a reckoning for how a trusted company like Crowdstrike has pushed out a dodgy patch like this, it just shouldn't be possible with correct procedures in place unless they've been compromised and what's gone out was never an authorised patch.

The resulting event is by far the biggest IT meltdown I can recall and as someone else has said the fix isn't easy if you have BitLocker running (which most IT literate companies will have on their EUDs) and don't have access to the recovery key (even worse if the issue has taken out your AD so you can't extract them centrally)

I'm just glad I work on an air-gapped secure network :p I think some colleagues are going to have busy weekends though 🙁

 
Posted : 19/07/2024 11:31 am
Posts: 2675
Free Member
 

Reminds me I must re-read Second Sleep by Robert Harris.

 
Posted : 19/07/2024 11:42 am
Posts: 1252
Free Member
 

it just shouldn’t be possible with correct procedures in place unless they’ve been compromised and what’s gone out was never an authorised patch.

That could be one possibility.

https://twitter.com/GossiTheDog/status/1814217357058842914

"I have obtained the Crowdstrike driver they pushed via auto update. I don't know how it happened, but the file isn't a validly formatted driver and causes Windows to crash every time."

https://twitter.com/GossiTheDog/status/1814217357058842914
span style="opacity: 0;position: absolute"> https://twitter.com/GossiTheDog/status/1814217357058842914

https://twitter.com/GossiTheDog/status/1814217357058842914

 
Posted : 19/07/2024 11:42 am
Posts: 7501
Full Member
 

How true this is for the Cloud. The man was totally ahead if his time.

There is no "cloud".  Its just someone else's server.  But because you've gone "cloud" instead of calling your IT guy to fix it you are now at the end of long queue of people waiting on the cloud provider to offer a fix*

*I know this is a massive over-simplification

 
Posted : 19/07/2024 11:42 am
Posts: 8552
Full Member
 

Fix for a BitLocker enabled system if you don't have the recovery key BUT you do need to have local admin rights (might be a bit confusing without the accompanying screenshots), I haven't validated this myself but it's been sent out as a fix by our internal IT:

Start Computer

Press ESC (this is on the BitLocker passcode entry screen and takes you into BitLocker Recovery mode)

Press ESC again

Skip drive

Choose Troubleshoot

Choose Advanced options

Choose Command Prompt

Write command “bcdedit /set {default} safeboot minimal” and press enter. Afterwards write command “exit” and restart pc.

During boot enter Bitlocker and windows will run in to safe mode – there you will need enter Local Admin login.

Open browser and location C:\Windows\System32\drivers\CrowdStrike\

Delete all files with starting “C-00000291*

Once its deleted, open C:\Windows\System32\cmd.exe

Write command “bcdedit /deletevalue {default} safeboot

Restart computer and normally login – computer should work

In case it doesn’t work make sure in step 10 you removed proper file “291” have to be in first part not second or third.

 
Posted : 19/07/2024 11:48 am
Posts: 2275
Full Member
 

I am sitting here with an update to our company's software that I've just finished writing. The news today has given me serious heebie-jeebies... think I'll do a little more testing, just in case haha

 
Posted : 19/07/2024 12:15 pm
 PJay
Posts: 4693
Free Member
 

Hope no-one has shares in Crowdstrike

"Crowdstrike has lost a fifth of its value in pre-market trading in the US - down 21% in unofficial trading.

If confirmed when US stock markets open later today, that is a loss of $16 billion in its overnight valuation."

https://www.bbc.co.uk/news/live/cnk4jdwp49et

 
Posted : 19/07/2024 12:21 pm
 MSP
Posts: 15334
Free Member
 

but I have not been able to get onto STW all morning until now.

That has been going on for a few days, I have posted about it a few times in the "report issues" sticky.

 
Posted : 19/07/2024 12:41 pm
Posts: 13388
Full Member
Posts: 7039
Free Member
 

How can a company like Crowdstrike possibly be "worth" $80Bn? That's an insane valuation even without this. What kind of secret snake oil are/were they selling?

(Posted from my work Linux laptop).

 
Posted : 19/07/2024 12:48 pm
Posts: 2295
Full Member
 

Crowdstrke begins to learn rapidly and eventually becomes self-aware at 2:14 a.m., EDT, on July 19th, 2024.

 
Posted : 19/07/2024 12:52 pm
Posts: 2275
Full Member
 

I kind of hope it is malicious, otherwise I'm imagining some poor programmer in Crowdstrike's office hiding under his desk in a puddle of urine, gibbering to themselves while the company goes into meltdown around them.

 
Posted : 19/07/2024 12:57 pm
 MSP
Posts: 15334
Free Member
 

It will be interesting to see what kind of "root cause analysis" gets released. IMO it is likely that all endpoint protection providers have similar processes, and trying to double guess who could have similar problems in the future from a one off incident probably isn't going to work. One theory would be that crowdstrile should now be much more careful for another few years at least, so would likely be more reliable for now than their competitors.

We run completely separate "chains" of computing in our operational controlling, maybe we should have different endpoint protection on each chain.

 
Posted : 19/07/2024 1:04 pm
Posts: 20535
 

How can a company like Crowdstrike possibly be “worth” $80Bn?

Their customers are huge, their product is industry leading (up to now) and really, really expensive.

Very much NOT snake oil either. They offer a million dollars to anyone who gets hacked while using their software, which they’ve never had to pay out on.

 
Posted : 19/07/2024 1:04 pm
Posts: 8552
Full Member
 

IMO it is likely that all endpoint protection providers have similar processes

I wonder if Microsoft will make anything of it (as in "I told you so" as they're forced to open up this sort of low level access to vendors for competition's sake), maybe in Windows 12 MS Defender will be the only endpoint protection client that can work at this level...

 
Posted : 19/07/2024 1:16 pm
Posts: 4824
Full Member
 

My boss has been" working" from home since the pandemic . Does this mean he might actually have to come in and do some actual hands on?

Bloody hope not as he is clueless

 
Posted : 19/07/2024 1:26 pm
 MSP
Posts: 15334
Free Member
 

I think crowdstrike is multi platform, which is 1 of the reasons companies use it, rather than having different security systems and processes for every operating system used.

 
Posted : 19/07/2024 1:33 pm
Posts: 12847
Free Member
 

They offer a million dollars to anyone who gets hacked while using their software, which they’ve never had to pay out on.
£1m is absolutely **** all to big company so that is probably worth as much as Giant’s warranty. Any hack that takes a megacorp offline for a prolonged period of time will certainly cost more than that in lost revenue/compensation to customers etc

how much do you think this **** up is going to cost Crowdstrike?

 
Posted : 19/07/2024 2:00 pm
Posts: 11688
Full Member
 

But the (previously) flakiest forum in the world just powers on without issue.

Have you visited the Wordle thread? It's chaos over there.

 
Posted : 19/07/2024 2:10 pm
 pk13
Posts: 2723
Full Member
 

Greg's is working don't panic.

So far we have had a support supply chain group try and implement a fix they found on the web.

This has not gone down well apparently.

 
Posted : 19/07/2024 2:12 pm
 5lab
Posts: 5542
Free Member
 

They offer a million dollars to anyone who gets hacked while using their software, which they’ve never had to pay out on.

they better hope this update wasn't a supply chain hack or their in serious debt 😀

 
Posted : 19/07/2024 2:20 pm
Posts: 31808
Free Member
 

Our local "Spotted" page on FB has gone full "cash is king, don't trust computers, or the government" which is quite unusual for us round here

 
Posted : 19/07/2024 2:29 pm
Posts: 8611
Free Member
 

To compound matters, there was actually an issue in US Central Azure region this morning too which meant storage became unlinked from VMs. Nice...

 
Posted : 19/07/2024 2:51 pm
Posts: 13060
Full Member
 

Pray for @longdog.

 
Posted : 19/07/2024 2:54 pm
Posts: 2335
Free Member
 

It's ok Sandwich,  no issues it would seem in the shops here, tea levels are restored 🙂

 
Posted : 19/07/2024 3:00 pm
Posts: 8391
Full Member
 

Phew, both bins emptied.

 
Posted : 19/07/2024 4:19 pm
Posts: 3946
Full Member
 

This is why we have a no change Friday policy at work. If something needs pushing out we do it Mon-Thu so no poor sod is working over the weekend if it goes wrong. Although we do have planned downtime at weekends for mission critical stuff.

 
Posted : 19/07/2024 4:36 pm
Posts: 2463
Full Member
 

@jeffl do you work at NASA?

 
Posted : 19/07/2024 4:58 pm
Posts: 76786
Free Member
 

On Monday I’ll be walking into my workroom and making curtains as usual.

It affects a different version of Windows.

The resulting event is by far the biggest IT meltdown I can recall and as someone else has said the fix isn’t easy

It's going to take, optimistically, weeks to resolve.

How can a company like Crowdstrike possibly be “worth” $80Bn? That’s an insane valuation even without this. What kind of secret snake oil are/were they selling?

Crowdstrike is - well, was - very highly regarded. It's also very highly expensive.

 
Posted : 19/07/2024 5:56 pm
toby and toby reacted
Posts: 3006
Free Member
 

Does anyone know if TicketMaster is affected? Trying to login and it says Email address not recognised despite it working yesterday..

Got a gig at weekend so need to access the tickets

 
Posted : 19/07/2024 5:56 pm
Posts: 76786
Free Member
 

Do you have an email copy of the tix maybe?

 
Posted : 19/07/2024 5:58 pm
Posts: 3006
Free Member
 

Unfortunately not.

 
Posted : 19/07/2024 6:00 pm
Page 1 / 2