Delta Air Lines vs. CrowdStrike: How The Airline Was Crippled By A Software Bug

Поделиться
HTML-код
  • Опубликовано: 27 сен 2024
  • Well, it looks like the dust has mostly settled in the dispute between Delta Air Lines and IT company CrowdStrike. This allows us to give a fairly comprehensive summary of everything that happened.
    As you may remember, CrowdStrike’s erroneous software update in July caused a near-global level of disruption impacting many airlines, hospitals, and emergency response systems. All in all, Forbes notes that about 8.5 million Windows devices were affected. For Delta Air Lines, disruptions resulted in the cancellation of about 7,000 flights over five days!
    And so for today’s video let’s examine everything that happened to Delta as a result of the CrowdStrike event, why the carrier was hit harder than other airlines, and the damages incurred.
    Our Social Media:
    / simpleflyingnews
    / simple_flying
    / simpleflyingnews
    Our Website
    simpleflying.com/
    For copyright matters please contact us at: legal@valnetinc.com

Комментарии • 20

  • @soccerguy2433
    @soccerguy2433 9 дней назад +9

    It should be mentioned that friday was Delta's busiest day of the year

  • @global2829
    @global2829 9 дней назад +23

    I flew out of ATL on Alaska Airlines that day. No wait to taxi since all the Delta flights were grounded - we got in early!

  • @jfmezei
    @jfmezei 9 дней назад +7

    Crowdstrike software runs in kernel mode, which means that when it tries to execute illegal instruction, access non existent memory or even divide by 0, the system cannot intercept this and kill only that process, the whole system goes down. And since the software starts early in the bot process, it would crash eveytime it booted.
    The flaw here is that the kernel mode software accepted unverified data from the internet without a user level software parsing it for validity before passing it to the kernel level software. This ia a bad design from Crowdsrike and bad decision from Delta for rellying on sofware from a company that doesn't know about basic precautions for kernel mode code.
    Each machine had to be rebooted with equivalent of special keypresses to avoid loading extensions after which you coudl delete the offending file and reboot normally. (this was documented early during the night by Crowdstrike). Remains to be seen if Delta IT staff were at work fixing the problem as soon as the fix was docuented or whether the fix started during regular work hours.

    • @apl175
      @apl175 8 дней назад

      Some systems - if they were "slow" were able to come up with network, download the latest crowdstrike update which deleted the offending file and reboot before crashing. But it's still no excuse for operating at ring level 0 at the kernel.
      I've heard this is a side effect of some EU anti-trust ruling that forces Microsoft to give unrestricted access to the kernel to third parties. I have not uncovered anything that validates this however.
      I believe Apple and MacOS take a different, safer approach which is pseudo-API driven for certain IO calls that might be interrogated by DLP and similar software.

    • @jfmezei
      @jfmezei 8 дней назад

      @@apl175 the Crowdstrike software evidently started with the corrupt file prior to requesting the latest update since the system would crash whenever it booted.
      You have kernel mode software that downloads something from the Internet and acts on it without validating it. That says a lot.

  • @Andrerc0
    @Andrerc0 9 дней назад +17

    Crowdstrike compensations to Delta are due

    • @aoe4_kachow
      @aoe4_kachow 9 дней назад +4

      one million skymiles

    • @zachattack83
      @zachattack83 9 дней назад

      @@aoe4_kachowwhat’s that good for an upgrade to premium economy?

  • @michaeloreilly657
    @michaeloreilly657 9 дней назад +5

    Pity they didn't go to court.
    It would have made an extremely interesting video for the channel.

  • @Toby-e1e
    @Toby-e1e 9 дней назад +6

    My flight got cancelled twice during this.

  • @soccerguy2433
    @soccerguy2433 9 дней назад +3

    Delta protects more devices with crowdstrike than American or United.
    Furthermore, Crowdstike cant help manually reboot computers in person anyways.

    • @jaymzx0
      @jaymzx0 8 дней назад

      Exactly. I was involved with remediation of a few thousand affected computers worldwide at my company. Repair required 'boots on the ground' once the procedure was identified, and luckily our processes allowed us to 'deputize' some technical staff to help remotely. Crowdstrike would need to offer up hundreds of engineers to fly all over the world to make a 10 minute repair, but that's not what they were offering. Microsoft would need to offer the same. Delta declining support by Microsoft to save face about ancient systems is 90% malarkey as Microsoft deals with computers older than that in some industries, such as industrial automation. If they had a support contract with another outside vendor to perform IT work and that vendor assured them they could handle it, that's likely why Delta said, "Nah, we got this. Thanks." Why engage another outside entity and take on the associated risks when you were promised your existing vendor would be just fine?
      Delta was likely concerned with access to their physical assets as well as entry into secure areas, as said in the video. If the devices were encrypted, they would need to be 'unlocked' to repair them, which could require additional access to be granted at the centralized IT level to obtain recovery keys. Delta is the third largest airline in the world by destinations, and I bet the vast majority of those destinations required a site visit. Given the sheer number of impacted devices in such far-flung locations, I personally cut Delta some slack at the IT level, and I hope some of their engineers got some time off afterward.
      How the company handled the canceled flights and their legal actions going forward is another matter altogether and I'm not privy enough to it to make an informed opinion. Unless a detailed account of the response by way of a third-party investigation is released to the public, it's all conjecture.

  • @alexschwager2645
    @alexschwager2645 8 дней назад +1

    the real villian in this are the hotel raising their prices

  • @philip7396
    @philip7396 9 дней назад +2

    The old console based scheduling system is probably the root cause of the cascading disruption. Most other airlines probably had a browser based application where they just needed a browser and VPN.

  • @Silent_Shishya
    @Silent_Shishya 9 дней назад +5

    Oh i was very happy about the Crowdstrike bug which locked out my office laptop. Got paid for doing nothing all day

  • @yunuscurrie3410
    @yunuscurrie3410 9 дней назад +1

    We got delayed 4 hours but we flew faster in probably a jetstream and arrived only 30 minutes delayed

  • @PeterFruits-hm8rc
    @PeterFruits-hm8rc 9 дней назад +1

    757

  • @charleshamilton9274
    @charleshamilton9274 9 дней назад

    My takeaway from this utterly preventable and foreseeable calamity? Delta’s garbage CEO complains bitterly regarding Cloudstrike’s indifference is only matched by Delta’s passengers complaint bitterly about the airline’s indifference. Did I mention this was preventable?