• mosiacmango@lemm.ee
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    3 months ago

    There are kernel modules, and then there are kernel modules.

    Based on conversations from the CTO of sentinel one, a crowdsrike competitor, the crowdstrike client is intentionally engineered with a lot of and way deeper hooks then most of the industry. This makes their engine powerful and very dangerous. The other vendors in the space touch the kernel as little as possible, moving everything they can into userspace to minimize any possible damage.

    The fact that crowdstrike was fully in the kernel and then running basically no tests while deploying updates is the reckless fuck up.