Live data from Hacker News

CrowdStrike will be liable for damages in France, based on the OVH precedent

thehftguy.com

11–20 of 285 posts

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#11

Holy shit (hits the fan). For sure CrowdStrike will be held accountable in several countries, but I believe that some conclusions need to be drawn also from a customer/user perspective. - Is it reasonable to grant such privilege access to a piece of software that ultimately is a black box ? - Is it reasonable to put a Microsoft / Commercial / Closed source OS in critical infrastructure ? If not considered as critical…

>- Is it reasonable to grant such privilege access to a piece of software that ultimately is a black box ?

As I said in the previous thread: explaining to execs that giving root to someone on your machines means they have root is a very difficult concept for them to understand.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#13

Awesome. Falcon has been widely known (for years) as an utter piece of shit (code wise). Maybe now ClownStrike will start testing it properly, hopefully thereby fixing the stability and other issues.

The problem is that you think that those managers are nice and reasonable people like yourself. They are not. What will happen is that some manager will yell at some other manager that will yell at some other manager that will yell at some tester that works on the cheapest virtual machine possible, on which it takes 5 minutes to log in and it disconnects after 2 minutes of idle. All the while, not changing anything.

I'm pretty sure that all their resources are allocated to lawyers right now and their managers try really hard to gaslight their customers by telling them it was not that bad, they came up with the fix really fast (ignoring the fact that the fix was not possible to be applied) and so on.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#14

Holy shit (hits the fan). For sure CrowdStrike will be held accountable in several countries, but I believe that some conclusions need to be drawn also from a customer/user perspective. - Is it reasonable to grant such privilege access to a piece of software that ultimately is a black box ? - Is it reasonable to put a Microsoft / Commercial / Closed source OS in critical infrastructure ? If not considered as critical…

> - Is it reasonable to have more than 70% of the computers/servers that run important infrastructure on the same OS / software ? How about the mitigation of the risks etc…

This is the problem as far as I'm concerned. Industry "best practice" is "use the same thing everywhere"

A diverse ecosystem is the best defence.

You could run 100% FreeBSD and be hit by say a hidden kernel bug which occurs on Jan 15th 2027 when unix time goes from 1.7b to 1.8b (I've seen that code before where time is assumed to be below X)

If you run 50% FreeBSD and 50% Windows you will only lose half your service.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#15
post #11

Holy shit (hits the fan). For sure CrowdStrike will be held accountable in several countries, but I believe that some conclusions need to be drawn also from a customer/user perspective. - Is it reasonable to grant such privilege access to a piece of software that ultimately is a black box ? - Is it reasonable to put a Microsoft / Commercial / Closed source OS in critical infrastructure ? If not considered as critical…

>- Is it reasonable to grant such privilege access to a piece of software that ultimately is a black box ? As I said in the previous thread: explaining to execs that giving root to someone on your machines means they have root is a very difficult concept for them to understand.

Then the exec should be held responsible?

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#16

The 10$ gift cards were just hilarious. How could they possibly expect anyone to take them seriously?

Was this possibly some way to influence liability limitation? If you accept a $10 gift card, could that be argued as an acceptance of compensation?

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#18
Can someone explain to me why the protections that Falcon provides, are not provided by the OS itself? I am not completely naive, I've secured quite a few critical Linux servers, but with Windows it seems that there do not exist the same clear roles of security. Contrast with Red Hat or even Canonical, where is feels like I'm (correctly) fighting the security of the systems to get them into a state where my users can use my applications.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#20
post #3

It's good to remind people that general liability waivers you often find with license agreements have no meaning outside of US jurisdiction if you're doing business in another jurisdiction.

The number of US tech businesses that are surprised they need, or think they can ignore the need, to obey employment and data protection laws when working in other jurisdictions is simply bonkers.
Post reply on HN