It’s Not The Next Outage

(This column is posted at www.StevenSavage.com, Steve’s Tumblr, and Pillowfort.  Find out more at my newsletter, and all my social media at my linktr.ee)

So the CrowdStrike Outage of 2024 happened. Actually, let me clarify, the CloudStrike Outage of July 2024. I might as well be clear because that was a doozy and it showed some wide-raging system instabilities. Also considering it was such a disaster maybe there’s another.

If you don’t know what I’m talking about, an update to some security software bricked a lot of windows machines in a disaster that shouldn’t have happened. If “scrutiny software shut down systems” sound bad, yes it was!

If “security disaster happened” AND you work in IT, AND your friends are nerds and/or work in IT, you know MY experience. I spent most of that Friday quietly losing my mind.

Of course there’s questions of “how do we avoid the next outage” which is sort of sad, because you’d kind of like there not to be one, or one as widespread. But I don’t think that’s quite the issue, preparing for the next Giant Ooposie misses two things.

First, this exposed just how vulnerable systems are, and I’m worried about intentional attacks. We saw in real time how a software update could destroy systems. We saw how people did – or didn’t recover. We saw where vulnerabilities might be. We wondered what would have happened had this been during another crises – hurricane, terrorist attack, etc.

CrowdStrike was a mix of blueprint, roadmap, and test run for how to screw up IT systems worldwide. This is what you get by accident, meaning intentional attacks are now much easier to pull off effectively. We need to worry about intention.

Imagine a CrowdStrike-like outage but with more destructive not just an issue that an in theory be fixed by booting 15 times. Something designed to not be recoverable, an IT WMD.


Secondly, we’ve just seen that many major systems are just plain vulnerable period. Everyone is on Windows, a lot of people use CrowdStrike, and recovery plans were individual. Though I was impressed with the global recovery, if you’re an IT pro or hang out with them (I do both) you know this was not easy.

Recovering from a one-shot, caught, error is one thing. But it’s a reminder that we are very vulnerable and might want to be questioning about how a lot of infrastructure is set up. How many smaller-scale disasters do we not see because it wasn’t big news? My general take is systems need to be easier to recover, more diverse, and honestly more walled off.

Also we need to stop depending on heroism in IT security. It should be incredibly boring.

The next CrowdStrike type error should not happen. But right now my concern is what happens intentionally, what may happen on a smaller scale at first, and that we’re probably not ready for either.

CrowdStrike was a wake-up call to so many things wrong in modern infrastructure, so many things that could go wrong. As much as the company screwed up massively there’s far more to worry about.

Steven Savage

The Scale of Victims

(This column is posted at www.StevenSavage.com, Steve’s Tumblr, and Pillowfort.  Find out more at my newsletter, and all my social media at my linktr.ee)

It sure seems there’s a lot of IT security breaches lately. In fact, it’s to the point where I can’t remember which one inspired this column. It’s probably just as well, since you can map whatever horrific violation of privacy you heard of this week onto this column. There, I’ve sort of written something relatively timeless because people are dumb.

One of the things I wonder about is why more CTOs, CIOs, and so forth aren’t being taken to court, followed by reporters, and in general held freaking responsible for their companies having lousy security. Yes there’s all sorts of shielding from accountability, but you think we’d see some effort, but I think one thing protecting them is that the company is seen mostly as a victim.

I’d argue that’s technically right, the companies were attacked by some external force. But treating companies as equivalent of people ignores their responsibilities. People, individual moral agents, can be victims, but corporations are not people and not moral agents, and treating them as victims like people lets them out of responsibilities. Sorry, Mitt Romney.

Think about a person who is a victim of a crime. Though people often try to blame victims, those blamers are usually both wrong and assholes (and sometimes justifying their own crimes). A person who is victim of a crime is a victim in that someone else chose to behave criminally.. Even if said victim enhanced their own danger it doesn’t remove the culpability of the criminal, who violated social and legal norms that people are expected to follow.

When I watch people shrug as corporation after corporation has customer records placed on the dark web, I see comments about how crappy their security is, but it doesn’t seem particularly judgmental. This impresses me as an echo of the don’t-blame-the-victim mentality.

But corporations are groups of people – organizations. That organization makes certain agreements and promises in order to exist. Security of data is, obviously, part of them. If one’s data is breached, despite the criminals actions, you also take responsibility as you are responsible. If you’re leadership, you should be on the line because you made a promise that this probably won’t happen.

Organizations are about promises and responsibility. Screw that up, and no matter why, someone has to pay as your failure hurt the organization and the people involved. You don’t have to restrain yourself on going after the people who did the actual crime, but corporations have made promises. If you can’t keep them, you’ve got a problem.

In fact, I’d say a corporation that suffers a data breach or similar failure must be investigated to see if it violated social norms. If the corporation made guarantees it could not and did not keep, if good faith effort was not made, the corporation was responsible. There is a failure of the company that echoes the action of the criminal, it too violated norms.

Of course we all know that if we at all ask this we’ll find a lot of corporations have done terrible at security. It’s all cost cutting, half-assed integration, and big bonuses. A lot of companies, if they were really investigated for security problems, would be locked down and sold off for being terrible.

(And yes, I work in Healthcare, which has insanely strict rules, but everyone should for everything, and we remember that these rules protect people.)

We don’t need to act like corporations are victims like people. If they can’t keep their promises, if security violations reveal they’ve done a poor job of protecting people, they’re part of the problem. Some of them should pay. Some shouldn’t exist.

Steven Savage

The Bullshit Waste Cascade

(This column is posted at www.StevenSavage.com, Steve’s Tumblr, and Pillowfort.  Find out more at my newsletter, and all my social media at my linktr.ee)

Watching once sort-of-reputable Rasmussen fall into the fever swamps of anti-vax bullshit is sad, but not surprising. I understand from some people I know that they’ve had weird biases for some time, if only for “marketing” purposes. Still, now their once good-ish name is now pretty much going to be used for whatever fantasies or con-jobs their leadership wants.

This has made me reflect on the damaging nature of Bullshit writ broad (in which I include disinformation and propaganda for “writ large.”). See, when we have people spewing things with no concern – or outright enmity towards – truth, it cascades downward. Having worked in many an organization as a Project Manager, you get very familiar with “cascade” effects of bad things, where one pebble starts an avalanche.

We’ve got a pretty bad Bullshit cascade going on in the world.

The basic Bullshit machine we see in assorted PR firms, hack pollsters, and what seems to be over half of political consultants is damaging enough. We have people buying dangerous products, getting wrong information, voting for grifters, authoritarian government manipulation, and more. But that’s the initial damage from Bullshit – the start of even worse.

As Bullshit spreads (and it certainly seems we’re good at spreading it these days) it worms it’s way into peoples minds. Truth fractures, lies become regarded as sacred, and people believe. The damage of Bullshit is long-term, and that may or may not be intentional, but it has to be kept in mind. In fact the unintentional Enduring Bullshit is probably even more damaging as we might not notice it – as I often see in various medical scams.

(For that matter, think of Bullshit as a kind of cultural equivalent of long COVID, if you want to get more depressed.)

Bullshit that endures seems to mate with other Bullshit. When you’re busy avoiding facts and truth after all, why not double up – weather you’re a propagandist or someone trying not to admit they’re wrong. Bullshit is used to justify or cross-fertilize Bullshit, like viruses combining. Soon you’re wondering how people merged 5G conspiracy theories with anti-vax conspiracy theories and aliens (something I’ve seen myself).

The systemic damage is bad, but remember that Bullshit consumes resources. The people who are busy creating Bullshit could be doing something more productive. The people fighting Bullshit would probably like to not have to, thank you. People bamboozled by Bullshit proceed to do bad things, wasting their time, hurting others, and creating more work for cleanup. The damage spreads throughout societies – and the planet.

Finally there is something that I think gets ignored about Bullshit but really needs our attention in these times – that Bullshit machines get people interested in doing more Bullshit. The people who pivot from Yoga to conspiracy theories to sell supplements. The folks who yes-and conspiracy theorists to sell their books or just get clicks (who are also crossbreeding Bullshit). It seems the more Bullshitters out there the more people see it as a life and career option.

If you ever felt like the age of the internet crossed with mass media is a lot of people lying to themselves and each other, yeah, you understand what I mean. Some bad things and bad people cascade throughout media, culture, and keep setting off more and more problems. Plenty of people look at them and think “I want a piece of that.”

Meanwhile humanity has a lot of crises to deal with, and the Great Bullshit Engine keeps going and maybe even expanding. Things are indeed more messed up than we may think because of these Bullshit effects.

If we’re going to try to dig out from the world’s problems, we’ll have to confront Bullshit, correct the damage, prevent Bullshit, and discourage it. It may help to realize just how bad the damage it causes is.

Steven Savage