Alex Dragusin


Home

CrowdStrike Suggestion: Future Changes to Deployment of Security Updates

In order to prevent the mess that was caused by the CrowdStrike update, which can happen with other providers and other critical systems is to add another layer of safety. This works in the context of large networks, not for the individual end user.

This layer can be made up of say 5 systems, this layer sits between the network of devices to be updated and the provider, these 5 systems act as a canary or a sandbox if you will, that is, when an update is rolled, these systems get updated first and monitored for a number of days etc, if these show no issues, then the green light is given to proceed. These systems would issue a GO signal and this acts as a vote, if one system gives a STOP then the update does not proceed further. This concept can be automated.

The technology exist to apply this idea, whether the will exist, that's another matter. To whom it might concern, please consider exploring this concept further. Situations like this can be avoided, it's no a fool proof method, as some issues take longer to manifest.

The Issue discussed on: Reddit | Hacker News





Back to main page


© Alex Dragusin. All Rights Reserved.