@[email protected] to TechnologyEnglish • edit-25 months agoTo what extent, if at all, would have CrowdStrike's faulty update have been easier to deal with with an immutable distro?message-square51fedilinkarrow-up1114arrow-down114
arrow-up1100arrow-down1message-squareTo what extent, if at all, would have CrowdStrike's faulty update have been easier to deal with with an immutable distro?@[email protected] to TechnologyEnglish • edit-25 months agomessage-square51fedilink
minus-square@[email protected]linkfedilinkEnglish2•5 months agoI did hear that one of their newer versions does use eBPF, but I haven’t even remotely looked into it. https://nondeterministic.computer/@mjg59/112816011370924959
minus-squarelemmynglinkfedilinkEnglish1•5 months agoThey do have a bpf sensor. It’s still shite, managing to periodically peg a CPU core on an idle system. They just lifted and shifted their legacy code into the bpf sensor, they don’t actually make good use of eBPF capabilities.
I did hear that one of their newer versions does use eBPF, but I haven’t even remotely looked into it.
https://nondeterministic.computer/@mjg59/112816011370924959
They do have a bpf sensor. It’s still shite, managing to periodically peg a CPU core on an idle system. They just lifted and shifted their legacy code into the bpf sensor, they don’t actually make good use of eBPF capabilities.