Holy shit (hits the fan). For sure CrowdStrike will be held accountable in several countries, but I believe that some conclusions need to be drawn also from a customer/user perspective. - Is it reasonable to grant such privilege access to a piece of software that ultimately is a black box ? - Is it reasonable to put a Microsoft / Commercial / Closed source OS in critical infrastructure ? If not considered as critical…
>- Is it reasonable to grant such privilege access to a piece of software that ultimately is a black box ? As I said in the previous thread: explaining to execs that giving root to someone on your machines means they have root is a very difficult concept for them to understand.
CrowdStrike will be liable for damages in France, based on the OVH precedent
21–30 of 285 posts
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#22Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#23The 10$ gift cards were just hilarious. How could they possibly expect anyone to take them seriously?
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#24The 10$ gift cards were just hilarious. How could they possibly expect anyone to take them seriously?
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#25From OP, in the OVH-case liability seems to override the contract / waivers when OVH was both the storage And backup provider and did not actively underline that this solution is suboptimal, in a situation where multiple data centers are physically very close. That's a chain of evidence.
For CrowdStrike, it is clear that the offering is to more mature counter parties (thus raising the B2B standard of evidence) and that CrowdStrike very essentially did not do / support staging, whatever. This is indeed bad industry practice, but one that can thought to be explicit from the start of the agreement. At least in my locale you either make explicit agreements OR industry standards are leading. We do not do industry standard X is pretty clear. Read the list in OP, replace CrowdStrike with Microsoft and then think of the international liability cases you've heard from where Microsoft was found liable for downtime, hacks and other issues.
Look, liabilities will always arise in such situations. But I expect only minor liabilities will arise. Mostly (AFAIK IANAL) the terms & conditions are applied in B2B-cases. This case is pretty obvious: you got what you signed up for. CrowdStrike with full scale access to your machines and no guarantees. On the other hand, Crowdstrike lost 125 billion in market cap. That's an indication of {liabilities + loss of future profits}. Pretty massive event for not being willing to do staging. But I expect it's mostly that CrowdStrike is tainted from now on. A friend of mine had a very bad stint as an employee of CrowdStrike recently and from what I learned from that case, I'm happy that the nature of the firm is somewhat more in the open now.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#26Earlier quoted context omitted.
>- Is it reasonable to grant such privilege access to a piece of software that ultimately is a black box ? As I said in the previous thread: explaining to execs that giving root to someone on your machines means they have root is a very difficult concept for them to understand.
Then the exec should be held responsible?
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#27The 10$ gift cards were just hilarious. How could they possibly expect anyone to take them seriously?
wait, that was not a joke?
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#28Holy shit (hits the fan). For sure CrowdStrike will be held accountable in several countries, but I believe that some conclusions need to be drawn also from a customer/user perspective. - Is it reasonable to grant such privilege access to a piece of software that ultimately is a black box ? - Is it reasonable to put a Microsoft / Commercial / Closed source OS in critical infrastructure ? If not considered as critical…
The hallmark of intelligence is to observe a situation and the structure of a system, reason about it, draw analogies with past experience and pre-emptively take corrective measures.
The stark truth is that we don't live in a "reasonable" world.
Poor governance, short termism, lack of transparency, incompetence, captured regulation, obsolete ideology etc. are not exceptions but rather the essence of how things "work".
The existential question is whether our demonstrable ability to achieve some learning will be sufficient to deliver solution on the face of increasing risks.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#29Holy shit (hits the fan). For sure CrowdStrike will be held accountable in several countries, but I believe that some conclusions need to be drawn also from a customer/user perspective. - Is it reasonable to grant such privilege access to a piece of software that ultimately is a black box ? - Is it reasonable to put a Microsoft / Commercial / Closed source OS in critical infrastructure ? If not considered as critical…
This is common enough in the corporate world and precedence in similar circumstances will come into play in various lawsuits.
Examples:
XYZ Security Guards: a third party physical security provider that hires people to watch and patrol buildings, assets, with access to keys, timetables, security logs, etc.
ABC Armoured Transport: third party physical transport provider for cash, sensitive documents, etc.
When AcmeCorp Inc. hire XYZ & ABC it's on the basis of reputation, contracts, and things generally not to do with peeking inside how the cake is baked (hiring records, etc).
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#30Eh, parts of this article aren't very reasonable. Even if they did a buttload of testing, it only takes one failure in one part of the chain (near the end).
They didn't test something they should have, sure, but obviously they didn't do "no testing whatsoever"