@PlutoisAPlanet @thelinuxEXP apparently they struck RHEL a month earlier https://www.reddit.com/r/linux/comments/1e98yal/crowdstrike_falcon_struck_redhat_kernel_as_well/
@ericdube @PlutoisAPlanet And since then, Linux devs have added an ABI that will prevent this type of issue. Crowdstrike is even using it now, if the system supports it
@thelinuxEXP @ericdube @PlutoisAPlanet@mastodon.social windows also has eBPF, and crowdstrike could have chosen to use it.
@gigantos @thelinuxEXP @PlutoisAPlanet Dave Plumber recently released a very good detailed update: https://www.youtube.com/watch?v=ZHrayP-Y71Q
I wonder, he didn't mention eBPF explicitly. Unless, is that was he's talking about at 6:20?