Logo

    Lessons to learn from the massive CrowdStrike outage

    enJuly 23, 2024
    What incident reminded us of Internet's fragility?
    Which sectors were affected by the CrowdStrike incident?
    What does DNS service host, and why is it fragile?
    What are concerns raised about cybersecurity industry concentration?
    Why is thorough software testing important before releases?

    Podcast Summary

    • Internet infrastructure vulnerabilitiesThe Internet's underlying infrastructure, including DNS services, is fragile and requires ongoing attention and care to address vulnerabilities

      The Internet and the online services we rely on daily are more complex and fragile than we often realize. Last week's cybersecurity incident, caused by a software update from CrowdStrike, served as a reminder of this. The incident affected various sectors, including healthcare systems, banks, and the travel industry. Kate Conger, a reporter for The New York Times, explained that the Internet is not just an intangible presence in the air, but a complicated system with underlying infrastructure. This infrastructure includes undersea cables, DNS services, and various apps and updates. The DNS service, which hosts websites, is particularly fragile and was not designed with the modern Internet in mind. The incident highlights the importance of understanding and addressing the vulnerabilities in this complex system. It's a reminder that the Internet, while essential, is not invulnerable and requires ongoing attention and care.

    • Tech infrastructure issuesSeemingly insignificant tech infrastructure issues can lead to profound consequences, causing widespread disruption and emphasizing the importance of dedicated professionals maintaining these systems.

      Even seemingly insignificant issues in technology infrastructure can lead to profound and far-reaching consequences. This was demonstrated by a recent incident involving CrowdStrike, a tech company that provides services to over half of Fortune 500 companies and various government agencies, including the top US cybersecurity agency. The incident itself was understated, with no dramatic system crash but rather a small problem that caused widespread disruption. This is not an unusual occurrence in tech history. For instance, there was a mass blackout in the Northeast in 1965 caused by a single Canadian relay station failure, leading to power outages in several states. These small infrastructure issues can have significant ripple effects, highlighting the importance of dedicated professionals working to maintain these systems and prevent potential disasters.

    • Cybersecurity industry concentrationThe cybersecurity industry is highly concentrated with a few dominant players, increasing concerns about potential monopolies and limited options for businesses.

      The cybersecurity industry is highly concentrated, with a few companies like CrowdStrike holding outsized reputations for handling the most complex and high-profile cyber attacks. These companies have extensive knowledge of online threats, making them valuable partners for businesses seeking robust protection. However, as Federal Trade Commission Chair Lena Khan points out, this concentration raises concerns about potential monopolies and limited options for businesses in need of alternative solutions during outages or dissatisfaction. Despite these concerns, the reliance on large cybersecurity firms with extensive resources remains common in the industry.

    • Software testing before updatesThorough software testing before updates are released is crucial to minimize potential problems, but even with the best testing, errors can still slip through, emphasizing the need for ongoing cybersecurity vigilance

      The CrowdStrike incident serves as a reminder of the importance of thorough software testing before updates are released. While it's not yet clear if CrowdStrike could have prevented the issue, it's common practice for companies to test updates on various machines and environments to minimize potential problems. Unfortunately, even with the best testing, errors can still slip through. In the aftermath of the incident, the US cybersecurity agency warned of potential phishing emails related to the CrowdStrike incident, highlighting the need for ongoing cybersecurity vigilance. As technology continues to evolve, it's crucial that companies prioritize testing and security measures to protect against potential vulnerabilities.

    Recent Episodes from Marketplace Tech

    The AI safety bill dividing Silicon Valley

    The AI safety bill dividing Silicon Valley

    Depending on whom you ask, a bill passed by California lawmakers last week could either save us from imminent AI doom or strangle innovation in Silicon Valley. The bill, SB 1047, is one of the first significant attempts to regulate artificial intelligence in the U.S. It’s supported by some high-profile voices in tech like Elon Musk. But critics say the regulation could stifle growth in Silicon Valley. On the show today, Marketplace’s Meghan McCarty Carino is taking a closer look at the arguments for and against SB 1047 with Chase DiFeliciantonio, a reporter at The San Francisco Chronicle, who has been following the bill’s journey through the Legislature.

    Marketplace Tech
    enSeptember 04, 2024

    Teenagers could be more susceptible to online “dark patterns”

    Teenagers could be more susceptible to online “dark patterns”

    Dark patterns are everywhere on the web. These are design tricks that manipulate users in some way and prompt them to give up information, money or just more of their time. A recent study from the Federal Trade Commission found three-quarters of all subscription apps and websites use at least one dark pattern, and a majority use multiple such tricks. Marketplace’s Meghan McCarty Carino spoke with Yanely Espinal, who covered the topic in this week’s episode of “Financially Inclined.” She said some common dark patterns include advertising that doesn’t look like advertising, online forms that come with check boxes pre-selected and something called confirm shaming.

    Marketplace Tech
    enSeptember 03, 2024

    Bytes: Week in Review — Telegram’s CEO arrested, SF startups boom and Meta pivots

    Bytes: Week in Review — Telegram’s CEO arrested, SF startups boom and Meta pivots

    This week: a report from venture capital firm SignalFire seems to show that despite all its problems, San Francisco is still the place to be for tech startups in the artificial intelligence space. Plus, why Meta is scrapping plans for a superpremium mixed-reality headset and aiming for a lite version instead. But first, the arrest of Telegram CEO Pavel Durov in France has sent shock waves through the tech world. Durov is facing a number of criminal charges. French authorities allege he is liable for illicit activities conducted on the encrypted messaging platform, including child sex abuse and drug trafficking, essentially because of a failure to moderate content. The case highlights longstanding tensions in the tech world between public safety and free speech. Marketplace’s Meghan McCarty Carino is joined by Natasha Mascarenhas, reporter at The Information, for her take on this week’s tech news.

    Marketplace Tech
    enAugust 30, 2024

    With campaign hacks, Iran takes a page from Russia’s playbook

    With campaign hacks, Iran takes a page from Russia’s playbook

    U.S. intelligence officials have confirmed that Iran was behind the recent cyberattack on former President Donald Trump’s election campaign. Using an approach called spear phishing, hackers sent personalized emails to campaign staff containing malware that allowed them to access private information and then leak it. Déjà vu, right? Javed Ali, a former senior counterterrorism official and a professor of practice at the University of Michigan, says Russia created the blueprint for this kind of attack. Marketplace’s Meghan McCarty Carino asked him for his reaction to Iran adopting the strategy.

    Marketplace Tech
    enAugust 29, 2024

    AI in the election: misinformation machine or meme generator?

    AI in the election: misinformation machine or meme generator?

    By now you’ve probably heard that generative artificial intelligence has the potential to supercharge the spread of disinformation in this election year. But with 68 days until Election Day, we haven’t seen the kind of widespread AI misinformation campaigns that experts warned about. Instead, as Will Oremus pointed out in a recent analysis for The Washington Post, we’ve seen a whole lot of silly AI-generated memes. He told Marketplace’s Meghan McCarty Carino that the most recent examples are coming from one particular presidential candidate.

    Marketplace Tech
    enAugust 28, 2024

    Court upholds block of California law aimed at protecting kids online

    Court upholds block of California law aimed at protecting kids online

    The California Age-Appropriate Design Code Act, passed in 2022, would be among the most sweeping pieces of legislation to protect kids from online harms — if it hadn’t become tangled up in court. The law has two basic requirements: first, that tech companies analyze and report on whether their products are harmful for children; second, that they minimize how much data they collect from those under 18. Earlier this month a federal appeals court found that first part likely violates the First Amendment, and upheld a lower-court decision blocking that part of the law. But it vacated an injunction on the second component, the part dealing with data privacy. The decision could point a way forward for similar laws, many of which have also run into legal challenges, Aaron Mackey, free speech and transparency litigation director at the Electronic Frontier Foundation, told Marketplace’s Meghan McCarty Carino.

    Marketplace Tech
    enAugust 27, 2024

    The loose, undefined guardrails of X’s AI image generator

    The loose, undefined guardrails of X’s AI image generator

    The social media platform X recently launched a new artificial intelligence feature for premium users: Grok-2, an AI model that can also generate images. And the outputs are a bit less censored than you might see with other similar tools. Experimenters online have been able to generate images of Donald Trump and Kamala Harris brandishing guns, Mickey Mouse smoking a cigarette and some far more disturbing tableaus. Grok claims to avoid images that are pornographic, excessively violent or intended to deceive and added it’s cautious about representing content that might infringe on existing copyright. But the guardrails certainly seem to be on the looser side, in keeping with owner Elon Musk’s hands-off approach to content moderation. Marketplace’s Meghan McCarty Carino spoke with Adi Robertson, senior tech and policy editor at the Verge, about Grok-2 and what she found while she tested the AI’s limits.

    Marketplace Tech
    enAugust 26, 2024

    Bytes: Week in Review — Dems’ tech platform, Google’s legal troubles and OpenAI’s newest partnership

    Bytes: Week in Review — Dems’ tech platform, Google’s legal troubles and OpenAI’s newest partnership

    On today’s show: Google deals with another legal headache. A federal appeals court revived a class-action lawsuit that had been dismissed concerning privacy violations by its Chrome browser. Plus, OpenAI, the maker of ChatGPT, has partnered up with another media brand, Condé Nast. But first, we can’t ignore the biggest happening of the week — the Democratic National Convention in Chicago, where the party formally nominated Vice President Kamala Harris for president with the help of big names in entertainment. Rapper Lil Jon revving up the presentation of the Georgia delegation’s votes was just one viral moment that came out of the convention. What didn’t come out of the gathering, though, were clear indications of the Harris campaign’s tech policy platform. Marketplace’s Meghan McCarty Carino spoke with Maria Curi, tech policy reporter at Axios, about what that platform might look like.

    Marketplace Tech
    enAugust 23, 2024

    What it’s like to be a content creator at the DNC

    What it’s like to be a content creator at the DNC

    New faces are mingling among the party faithful and the swarm of journalists at the Democratic National Convention in Chicago this week. In a bid to reach younger, more online voters, the DNC invited 200 content creators to cover the convention. One of them is Malynda Hale, who’s been sharing her experience with her more than 50,000 followers on Instagram. Creators like her, she said, have their own part to play at the event. Marketplace’s Meghan McCarty Carino spoke to Hale how it’s been going at the convention.

    Marketplace Tech
    enAugust 22, 2024