Restoring PCs Affected by CrowdStrike… with Barcodes?
Restoring PCs Affected by CrowdStrike… with Barcodes?

8.5 million systems, billions of dollars in losses… the CrowdStrike event turned the commercial and financial world on its head. Now, stories and details about the slow recovery are starting to emerge. Saving time is a fundamental goal when you have to revive hundreds of computers, and the technical team at the Australian branch of Grant Thornton International found an excellent shortcut: using barcodes to quickly enter BitLocker keys into their terminals.

As we explained in our previous article, repairing the fault caused by the erroneous CrowdStrike update isn't particularly complicated… as long as we're talking about a single computer. Some affected companies found thousands of terminals out of action, and although Microsoft put a cap on the final number (8.5 million, to be precise), let's just say many lost their vacations.

With that in mind, we come to the Australian branch of Grant Thornton International (consulting, audits, tax services, etc.), with hundreds of terminals and "no less than a hundred servers" at its disposal. In addition to suffering CrowdStrike's fury, all its systems are encrypted with BitLocker and protected via LAPS (Local Administrator Password Solution), so besides repairing PCs, those responsible must enter the 48-digit key in each case, without exceptions.

CrowdStrike, BitLocker, and Barcodes to the Rescue

Restoring PCs Affected by CrowdStrike… with Barcodes?
In the image, a technician uses a barcode reader to read the BitLocker keys of a system affected by the CrowdStrike bug.

Obviously, the Grant Thornton folks did their homework and stored the BitLocker keys… but there are hundreds of computers. The company decided to prioritize recovery of the servers and the process began by hand; however, the terminals would need an automated solution, something delicate considering that BitLocker keys cannot be distributed. Reading a 48-digit key over the phone doesn't make much sense either, but systems engineer Rob Woltz remembered an essential detail: when a computer starts, barcode readers behave the same way as a keyboard.

Woltz and his colleagues created a special script that converted all BitLocker keys into barcodes, using a secure terminal. The rest of the work was left to a standard USB reader, priced at $36. Last Monday, remote employees received instructions to bring their locked terminals to the IT department and connect the reader to each one, with the aim of speeding up the entry of BitLocker keys and LAPS credentials. With this method, the CrowdStrike error consumed an average of 3 to 5 minutes per terminal, while manual repair of the servers took 20 minutes each time.

On the Web, the solution has not only been celebrated, but some comments suggest the possibility of using QR codes to further automate the process.

Sources: The Register, LinkedIn