Southwest Airlines, the fourth largest airline in the US, is seemingly unaffected by the problematic CrowdStrike update that caused millions of computers to BSoD (Blue Screen of Death) because it used Windows 3.1. The CrowdStrike issue disrupted operations globally after a faulty update caused newer computers to freeze and stop working, with many prominent institutions, including airports and almost all US airlines, including United, Delta, and American Airlines, needing to stop flights.
Windows 3.1, launched in 1992, is likely not getting any updates. So, when CrowdStrike pushed the faulty update to all its customers, Southwest wasn’t affected (because it didn’t receive an update to begin with).
The airlines affected by the CrowdStrike update had to ground their fleets because many of their background systems refused to operate. These systems could include pilot and fleet scheduling, maintenance records, ticketing, etc. Thankfully, the lousy update did not affect aircraft systems, ensuring that everything airborne remained safe and were always in control of their pilots.
I feel like every article out there is missing this and keeps blaming Windows Update vs an update pushed to a specific piece of software by a third-party developer. I get end-users not understanding how things work but tech writers should be more knowledgeable about the subject they write about for a living.
Windows 3.1 didn’t have the BSOD. It just froze. I remember with Windows NT 4, when we first got the BSOD, being so grateful that Microsoft decided to actually tell us that our computer wasn’t going to recover from the error. Otherwise, we’d just be sitting there, waiting, hoping it would unfreeze itself.
Windows 3.1 did have a BSOD. It wasn't always fatal, you could try to hit enter to go back to Windows, but most of the time it wasn't really recoverable, Windows often wouldn't work right afterwards.
I ran into them all the time in 3.11 on our 486 which had some faulty RAM (the BSOD would even be scrambled). If we could get back to Windows after that, it'd just be in a zombie state where moving the mouse around would paint stuff over whatever was left on screen, and wouldn't respond to clicks or keypresses.
Are you sure? I remember a long time ago being able to trigger a BSOD by opening Windows Calculator and dividing any number by 0. And I'm pretty sure that was 3.1 or 3.11.
In fact, I remember being able to change the color of the BSOD.
Windows 3.1 absolutely did have a BSoD, and as the other person mentioned, sometimes you could press a key and the OS would recover. More often than not you needed to reboot, though. Our family PC would BSoD all the damn time, and I had to put up with it throughout a good portion of my early childhood until my dad finally bought a Windows 98 SE PC. But that OS also had its fair share of instability issues. The "illegal operation" error message was a near-daily occurance.
It wasn't until we got our first NT-based machine (XP) that we stopped having constant issues with Windows. The DOS-based Windows OSes were notoriously unstable.
Old programming languages are fine. Hard to maintain though. But they all compile down to machine code at the end of the day.
Old operating systems on the other hand means they are vulnerable to all kinds of exploits that have been discovered in that OS over the past few decades. That's a much bigger problem.
One X user suggested that the company switch to Windows XP—it’s also no longer updated, and it can run Windows 3.1 applications via compatibility mode.
Maybe that was a joke, but if anything that would reduce their security. Windows 3.1 and 95 are old enough that they can't even run most stuff from the last two and a half decades, which probably protects them. XP is just new enough, and plenty old enough, to be very risky.
Reminds me of an episode of Ghost in the Shell where a hacker in a hyper-advanced cyberised society was using floppy disks as a storage medium because they were so slow.
One of the background details I liked in Ghost in the Shell was how the high-end data analysts and programmers employed by the government did their work using cybernetic hands whose fingers could separate into dozens of smaller fingers to let them operate keyboards extremely quickly. They didn't use direct cybernetic links because that was a security vulnerability for their brains.
Holy crap, they are serious. I though I was on !programmer_humor@programming.dev for a minute. I sure hope none of those computers are connected to the internet. There's a massive number of vulnerabilities in windows 3.1 and windows 95.
Yes, the update bricked the systems, meaning the software that powers their business was unaccessible, reinstalling any version of windows would not restore the software built on top of the os. Thus why it became a huge ordeal rather than a simple update push from Microsoft, a bricked system can’t receive a fix remotely.
And not sure whether there's been a plot play with the Katana fleet (all ships were slaved to the flagship, all crews including that of the flagship caught a virus causing them to go mad and die, and while they were still alive, the fleet jumped in unknown direction ; it was found later and ships reused by sides of the civil war) where its obsolete electronics and software were actually an advantage security-wise.
Though in that universe it seems that interfacing and integrating wildly different systems is more or less a normal thing, since there are lots of planets, lots of races and some things still in operation are few centuries old.
You just know there's an SMB share somewhere with no password, where files filled with unencrypted customer details get dumped for processing by an ancient AS400 server.
Windows 3.1 not being updated by Microsoft has nothing to do with Crowdstrike rolling out an update to their Falcon Sensor software including a file with 42kB of zeroes.
On Windows 3.1 you probably can't run Falcon Sensor, so in that way it could be related. But it seems way more likely that Southwest Airlines simply didn't use Falcon Sensor on their normal Windows 10 or whatever clients.
There are probably competitors to Crowdstrike, at least some companies would be customers to one of them.
Ahhhh, the Technology Trap. The modern world has become a mere handful of bad zeros away from having this house of cards crash down and kill almost everyone.
Technology is great and makes our modern society comfy and great. But it also can be the Sword of Damocles. When will that slender thread break and kill us all?
Everything we know about this is that it was a disaster waiting to happen. Why the heck aren't the airlines using Linux instead of Windows for critical stuff? How about something like...Chrome OS? Then you don't need CrowdStrike because your OS is already secure because of the built in VMs and because it is Linux. Pay google for support and no updates unless there is something critical.
edit: Lots of Microsoft lovers here lol. And missing the point which is that using the most well known consumer OS for critical stuff like keeping flights going is begging for trouble.
Mainly people are down voting you because Linux had also been affected by Crowdstrike before. Only a few months ago at that. There aren't any more defenses in Linux systems against this kind of problem than there are in Windows ones. This isn't even strictly speaking a security issue either. It's more like a bug in critical software that just happens to be security related. It's a bit like when that Grub update broke some people's arch setups.
It's not that Linux can't have security problems. I still remember the very first internet virus in 1987 that traveled thru Unix machines. But Windows is the worst OS for critical systems precisely because it is the most common OS. Anything is better than windows. Linux, MacOS, or even an old IBM mainframe OS and those awful tn3270 terminals. Also, Chrome OS in particular has VMs instead of other VMs. It really is designed to be much more secure than Windows.
It’s more like a bug in critical software that just happens to be security related.
And so the cure is the same as the disease. Or actually worse in this case. The very fact that systems were constantly updated was itself the problem rather than the solution to the problem. How did nobody realize this was going to happen sooner or later?
Linux had also been affected by Crowdstrike before.
I'm guessing Crowdstrike issues a lot more Windows updates than Linux updates?
The disaster likely happened because Crowdstrike didn't do any phased rollouts or testing, which would have picked up a glitch like these before it could brick countless millions of systems. Blaming Microsoft for what is most likely gross negligence from a major cybersecurity firm is downright disingenuous.
Also, recommending an overglorified web browser baked into an OS which can only run web and Android applications to run critical infrastructure is downright laughable, ESPECIALLY when Google are known for their downright nonexistent customer support.
People use Windows because it's the most well-known and used OS on the market, and because Microsoft is a multi-billion dollar tech giant with a dedicated customer support and tech team to fix issues posthaste.
I'm not blaming Microsoft. I am blaming companies for using Microsoft for critical systems.
Also, recommending an overglorified web browser baked into an OS which can only run web and Android applications to run critical infrastructure is downright laughable,
You not understanding that ChromeOS is a highly secure Linux computer is that can run any Linux program is downright laughable ignorance.
ESPECIALLY when Google are known for their downright nonexistent customer support.
Their software is way too widely used to provide you with free customer support. Microsoft is no different.