EuroBSDCon 2025

Security through Diversity
2025-09-27 , D1

On July 19, 2024 Crowstrike issued an update for its IDS system for the Windows operating system. This fateful update happened to cause crashes of IT systems that relied on the Windows/Crowdstrike around the world with dire consequences of closing entire airports hampering health care and ending up costing potentially billions of USDs.

A common theme among those whos operations ground to a stop during this outage was, admittedly with 20/20 hindsight, was a reliance on one particular combination of technologies. Windows and crowdstrike are, presumably, both fine technologies chosen by the largest organizations on the planet. However, they are not the only combination of OS and IDS capable of operating, even in high stakes environments.

This talk will discuss how the outcome of the July 19 event and similar events causing mass outages could be less disruptive by introducing a measure of diversity in the technical solutions. We will also discuss ways to create diverse solutions while minimizing the extra cost.

Kent Inge has been working with Software Engineering since 2005. In that time, he has contributed to numerous projects and systems. He has also published several academic articles as well as some opinion pieces on various topics in Software Engineering including in application security.