• CompactFlax@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    90
    ·
    11 hours ago

    Oh cool. Cool cool cool.

    Crowdstrike processes their signature files in kernel mode. Defender helpfully pastes malware over system files. Ivanti has a new critical vulnerability every week or so. Why are security vendors incompetent?

    • Brkdncr@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      5 hours ago

      Crowdstrike has an impressive marketing budget.

      BlackBerry cylance was a better product in every aspect but BB didn’t try to market it after aquiring it.

    • shameless@lemmy.world
      link
      fedilink
      arrow-up
      38
      ·
      10 hours ago

      Because they know they have such a chokehold on the market. I remember back in the XP days it felt like every year there was a new top tier security product that people were trying.

    • slazer2au@lemmy.world
      link
      fedilink
      English
      arrow-up
      24
      ·
      10 hours ago

      Because all software is insecure.

      You hear a lot about them because they are used in government and large enterprise environments when threat actors love to attack.
      Having a responsible disclosure process where they announce problems so their customers know it’s patching time. It’s better then it use to be where a vendor threw out a patch and if you didn’t patch because the vendor didn’t say why the patch was released.

      • tidderuuf@lemmy.world
        link
        fedilink
        arrow-up
        18
        ·
        8 hours ago

        There’s a reason why Isolated Networks are big money these days. Everyone expects their shit connected to the internet will be hit eventually and anyone that thinks they are safe are probably already being hit.

        • luciferofastora@feddit.org
          link
          fedilink
          arrow-up
          1
          ·
          5 hours ago

          anyone that thinks they are safe are probably already being hit.

          Is that the IT Sec version of “If you think you’re never wrong, you already are”?

          • tidderuuf@lemmy.world
            link
            fedilink
            arrow-up
            2
            ·
            4 hours ago

            I probably should have used the analogy my VD doctor gave me, “If you keep dippin your tip even with the best of protection on you’ll eventually find a walking biohazard that even I can’t bring you back from.”

    • Barbecue Cowboy@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      9
      ·
      9 hours ago

      Some of it is incompetence, but some is… more complicated incompetence. A lot of the weirdness you see is where some executive somewhere had a problem that affected him and had enough money/clout to throw around that they could make whatever just happen. Microsoft is the worst at this.