Live data from Hacker News

CrowdStrike will be liable for damages in France, based on the OVH precedent

thehftguy.com

31–40 of 285 posts

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#31

> "It is not an isolated incident. The same thing happened few weeks earlier with the CrowdStrike agent on Linux, nuking the system and there may be other occurrences before." Is there a link with this incident?

"CrowdStrike broke Debian and Rocky Linux months ago", https://news.ycombinator.com/item?id=41018029

"CrowdStrike's Falcon Sensor also linked to Linux kernel panics and crashes", https://news.ycombinator.com/item?id=41030352

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#32
post #13

Awesome. Falcon has been widely known (for years) as an utter piece of shit (code wise). Maybe now ClownStrike will start testing it properly, hopefully thereby fixing the stability and other issues.

The problem is that you think that those managers are nice and reasonable people like yourself. They are not. What will happen is that some manager will yell at some other manager that will yell at some other manager that will yell at some tester that works on the cheapest virtual machine possible, on which it takes 5 minutes to log in and it disconnects after 2 minutes of idle. All the while, not changing anything.…

hopefully the lawyers are demanding payment in advance

in many countries there are very strict limits on excluding liability for negligence

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#33
post #20
post #3

It's good to remind people that general liability waivers you often find with license agreements have no meaning outside of US jurisdiction if you're doing business in another jurisdiction.

The number of US tech businesses that are surprised they need, or think they can ignore the need, to obey employment and data protection laws when working in other jurisdictions is simply bonkers.

Well, it'd be a lot easier if most US entities understood that M/d/yy(yy) format is rare, or that default to Frankenstein degrees is pretty much the same/awkward (even Microsoft reset their weather widget to F on regular basis).

The root of issue, not understanding local laws/culture, is very similar - surrounded by a vast market/culture (US +Canada) dulls your senses for the rest of the globe.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#35

Can someone explain to me why the protections that Falcon provides, are not provided by the OS itself? I am not completely naive, I've secured quite a few critical Linux servers, but with Windows it seems that there do not exist the same clear roles of security. Contrast with Red Hat or even Canonical, where is feels like I'm (correctly) fighting the security of the systems to get them into a state where my users can…

How do you actively detect a malware agent running in user space using stealth or a kernel. Authors of such are fully aware of Linux hardening like SELinux / AppArmor and work around it.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#36

Can someone explain to me why the protections that Falcon provides, are not provided by the OS itself? I am not completely naive, I've secured quite a few critical Linux servers, but with Windows it seems that there do not exist the same clear roles of security. Contrast with Red Hat or even Canonical, where is feels like I'm (correctly) fighting the security of the systems to get them into a state where my users can…

I read an article that stated that Microsoft lost an anti-trust court case against the EU in which the EU mandated that they allow third party competitors to provide this service. Microsoft has its own solution called Windows Defender.

https://www.theregister.com/2024/07/22/windows_crowdstrike_k...

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#37

Holy shit (hits the fan). For sure CrowdStrike will be held accountable in several countries, but I believe that some conclusions need to be drawn also from a customer/user perspective. - Is it reasonable to grant such privilege access to a piece of software that ultimately is a black box ? - Is it reasonable to put a Microsoft / Commercial / Closed source OS in critical infrastructure ? If not considered as critical…

EDRs are the devil's spyware. Especially since corporate "security" people are now pushing for EDRs to run on Linux. Argument is that the cloud nature of the thing makes it necessary that it runs everywhere. Fact is, since my company forced me to install this black box, my system is definitely less secure. Before that, I didnt have a single incoming port enabled. Now, my system talks to all sorts of external things which I have no knowledge about and no control over.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#38
post #9

I was aware of this being the case when dealing with consumers, but had assumed that because B2B contracts are assumed to be between 2 sophisticated parties that there is little legislative protection that could override the terms of the contract. My understanding of law is generally UK based, but I'm not aware of legislation what would supersede a contract term limiting liability when the event that created the liab…

Well for starters it did impact health and safety domains; hospitals and emergency services were severely degraded. There absolutely will be preventable deaths directly traceable to Crowdstrike.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#39
post #20
post #3

It's good to remind people that general liability waivers you often find with license agreements have no meaning outside of US jurisdiction if you're doing business in another jurisdiction.

The number of US tech businesses that are surprised they need, or think they can ignore the need, to obey employment and data protection laws when working in other jurisdictions is simply bonkers.

It's not unusual in the US to assume the US are the only planet in the universe.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#40

Can someone explain to me why the protections that Falcon provides, are not provided by the OS itself? I am not completely naive, I've secured quite a few critical Linux servers, but with Windows it seems that there do not exist the same clear roles of security. Contrast with Red Hat or even Canonical, where is feels like I'm (correctly) fighting the security of the systems to get them into a state where my users can…

Windows does have Defender, which does some amount of tracking signatures and heuristics of various types of malware.

It has not, however, proved enough to fend off different real world problems like ransomware.

Hence, the market for 3rd party solutions that are more aggressive. And to keep up with real world threats, they have to update often. And have to run at high privilege levels. So now you have the situation where those third-party solutions have the ability to create a bsod and/or a boot loop. Which should mean that they have a very well thought out way to roll out updates.

Post reply on HN