How a Faulty CrowdStike Update Crashed Computers around the World

FILE PHOTO: A man types on a computer keyboard in front of the displayed cyber code in this illustration picture taken on March 1, 2017.REUTERS/Kacper Pempel/Illustration/File Photo
FILE PHOTO: A man types on a computer keyboard in front of the displayed cyber code in this illustration picture taken on March 1, 2017.REUTERS/Kacper Pempel/Illustration/File Photo
TT
20

How a Faulty CrowdStike Update Crashed Computers around the World

FILE PHOTO: A man types on a computer keyboard in front of the displayed cyber code in this illustration picture taken on March 1, 2017.REUTERS/Kacper Pempel/Illustration/File Photo
FILE PHOTO: A man types on a computer keyboard in front of the displayed cyber code in this illustration picture taken on March 1, 2017.REUTERS/Kacper Pempel/Illustration/File Photo

Airlines, banks, hospitals and other risk-averse organizations around the world chose cybersecurity company CrowdStrike to protect their computer systems from hackers and data breaches.

But all it took was one faulty CrowdStrike software update to cause global disruptions Friday that grounded flights, knocked banks and media outlets offline, and disrupted hospitals, retailers and other services.

“This is a function of the very homogenous technology that goes into the backbone of all of our IT infrastructure,” said Gregory Falco, an assistant professor of engineering at Cornell University. “What really causes this mess is that we rely on very few companies, and everybody uses the same folks, so everyone goes down at the same time.”

The trouble with the update issued by CrowdStrike and affecting computers running Microsoft's Windows operating system was not a hacking incident or cyberattack, according to CrowdStrike, which apologized and said a fix was on the way.

But it wasn't an easy fix. It required “boots on the ground” to remediate, said Gartner analyst Eric Grenier.

“The fix is working, it’s just a very manual process and there’s no magic key to unlock it,” Grenier said. “I think that is probably what companies are struggling with the most here.”

While not everyone is a client of CrowdStrike and its platform known as Falcon, it is one of the leading cybersecurity providers, particularly in transportation, healthcare, banking and other sectors that have a lot at stake in keeping their computer systems working.

“They’re usually risk-averse organizations that don’t want something that’s crazy innovative, but that can work and also cover their butts when something goes wrong. That’s what CrowdStrike is,” Falco said. “And they’re looking around at their colleagues in other sectors and saying, ‘Oh, you know, this company also uses that, so I’m gonna need them, too.’”

Worrying about the fragility of a globally connected technology ecosystem is nothing new. It's what drove fears in the 1990s of a technical glitch that could cause chaos at the turn of the millennium.

“This is basically what we were all worried about with Y2K, except it’s actually happened this time,” wrote Australian cybersecurity consultant Troy Hunt on the social platform X.

Across the world Friday, affected computers were showing the “blue screen of death” — a sign that something went wrong with Microsoft's Windows operating system, The AP reported.

But what's different now is “that these companies are even more entrenched,” Falco said. "We like to think that we have a lot of players available. But at the end of the day, the biggest companies use all the same stuff.”

Founded in 2011 and publicly traded since 2019, CrowdStrike describes itself in its annual report to financial regulators as having “reinvented cybersecurity for the cloud era and transformed the way cybersecurity is delivered and experienced by customers.” It emphasizes its use of artificial intelligence in helping to keep pace with adversaries. It reported having 29,000 subscribing customers at the start of the year.

The Austin, Texas-based firm is one of the more visible cybersecurity companies in the world and spends heavily on marketing, including Super Bowl ads. At cybersecurity conferences, it's known for large booths displaying massive action-figure statues representing different state-sponsored hacking groups that CrowdStrike technology promises to defend against.

CrowdStrike CEO George Kurtz is among the most highly compensated in the world, recording more than $230 million in total compensation in the last three years. Kurtz is also a driver for a CrowdStrike-sponsored car racing team.

After his initial statement about the problem was criticized for lack of contrition, Kurtz apologized in a later social media post Friday and on NBC's “Today Show.”

“We understand the gravity of the situation and are deeply sorry for the inconvenience and disruption,” he said on X.

Richard Stiennon, a cybersecurity industry analyst, said this was a historic mistake by CrowdStrike.

“This is easily the worst faux pas, technical faux pas or glitch of any security software provider ever,” said Stiennon, who has tracked the cybersecurity industry for 24 years.

While the problem is an easy technical fix, he said, it’s impact could be long-lasting for some organizations because of the hands-on work needed to fix each affected computer. “It’s really, really difficult to touch millions of machines. And people are on vacation right now, so, you know, the CEO will be coming back from his trip to the Bahamas in a couple of weeks and he won’t be able to use his computers.”

Stiennon said he did not think the outage revealed a bigger problem with the cybersecurity industry or CrowdStrike as a company.

“The markets are going to forgive them, the customers are going to forgive them, and this will blow over,” he said.

Forrester analyst Allie Mellen credited CrowdStrike for clearly telling customers what they need to do to fix the problem. But to restore trust, she said there will need to be a deeper look at what occurred and what changes can be made to prevent it from happening again.

“A lot of this is likely to come down to the testing and software development process and the work that they’ve put into testing these kinds of updates before deployment,” Mellen said. “But until we see the complete retrospective, we won’t know for sure what the failure was.”



S.Africa's Iconic Protea Flower Relocates as Climate Warms

Protea flower grower Nico Thuynsma cultivates the blooms north of Johannesburg, 1,500 km (930 miles) from their natural home at the southern tip of Africa. Phill Magakoe / AFP
Protea flower grower Nico Thuynsma cultivates the blooms north of Johannesburg, 1,500 km (930 miles) from their natural home at the southern tip of Africa. Phill Magakoe / AFP
TT
20

S.Africa's Iconic Protea Flower Relocates as Climate Warms

Protea flower grower Nico Thuynsma cultivates the blooms north of Johannesburg, 1,500 km (930 miles) from their natural home at the southern tip of Africa. Phill Magakoe / AFP
Protea flower grower Nico Thuynsma cultivates the blooms north of Johannesburg, 1,500 km (930 miles) from their natural home at the southern tip of Africa. Phill Magakoe / AFP

On his farm two hours north of Johannesburg, Nico Thuynsma gestured towards thousands of orange, yellow and pink proteas in flower and thriving 1,500 kilometers (930 miles) from their natural home at the southern tip of Africa.

"They're all different," the 55-year-old farmer said of the assorted blooms from the diverse Proteaceae family that has more than 350 species in South Africa, from firework-like "pincushion" varieties to delicate "blushing brides".

He picked out a majestic pink and white crown, nearly the size of his head, that has taken four years to reach its impressive size. "The King Proteas are very slow to grow," Thuynsma said.

The largest of the proteas, the King Protea, is South Africa's national flower.

It has lent its name to the national cricket team and countless brands. It features on the currency and is the logo for South Africa's presidency this year of the G20 group of leading economies, which convenes a summit in November.

It is also the country's largest flower export with more than 10 million stems sent abroad last year, worth close to 275 million rand ($15 million), according to the Cape Flora industry organization, said AFP.

Its status offers the King Protea some protection but almost half of South Africa's other protea species face extinction because of pressures on their native habitats in the mountains of the Cape, according to South Africa's National Biodiversity Institute (SANBI).

These include habitat loss to agriculture, the proliferation of invasive alien species and "changes to natural fire cycles", SANBI said in a 2021 report.

Icon

"People come to South Africa to see proteas," Nigel Barker, a professor in plant sciences at the University of Pretoria, told AFP. "It's the plant equivalent of the elephant or the lion."

Most proteas are endemic or semi-endemic to the Cape Floral Kingdom biome of "fynbos" ("fine bush") that stretches across the southern tip of South Africa and is one of the world's richest flora biodiversity hotspots.

But climate projections predict "hotter, drier conditions", Barker said. "We'll be looking at a completely different vegetation type in the future, semi-desert almost in some places."

"Many species, because they're so range-restricted, will probably go extinct under those scenarios," he said.

"The only solution we have is to cultivate them artificially... in greenhouses or farms where you control irrigation," Barker said.

An example is Thuynsma's farm in the grasslands of the north, where he began planting proteas three decades ago.

Here, winters are dry and frosty, and the summers rainy -- conditions very different to those in the far south where the proteas are at home.

Gel for irrigation

Through trial and error, Thuynsma has been able to cultivate close to 200 protea varieties, including some long forgotten and abandoned by farmers in their original habitats.

In his latest experiment, he has planted 36 varieties with just two liters (four pints) of saturated gel for irrigation.

"I hope to unlock the power of some of these varieties," Thuynsma said. "They come from the Western Cape out of very harsh conditions, so they do have it in them."

"I learn from them, I learn with them. And, hopefully, in the future I can advise my nursery public -- and even estates -- how to plant this lovely fynbos without irrigation," he said.

"I don't think I have a solution for climate change," he joked, crouched over a small seedling in freshly turned soil. "But I do have a solution: to plant proteas."

A few meters (yards) away, in a warm nursery, thousands of protea sprouts awaited their turn in the soil.

"I love them, I protect them, I collect them," Thuynsma said. "The protea is part of South Africa's DNA."