What is hilarious to me is how the US government or courts doesn't seem to give a shit about this. Corporativism in US is a thing. Companies can brick hospital systems killing patients, drive self-driving cars and run over people but don't get sued, and if they do, they settle for very little. Just look at the recent Boeing incident where people were killed, the company clearly misled the US authorities and settled o…
CrowdStrike will be liable for damages in France, based on the OVH precedent
101–110 of 285 posts
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#102Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#103Earlier quoted context omitted.
> surrounded by a vast market/culture (US +Canada) US companies don't think about Canada as anything but an afterthought, and struggle with the same issues here that you just mentioned. Canada is metric, uses different spellings (closer to UK English.. colour, not color [Chrome just marked my spelling as wrong despite me having Canadian English as my setting]) and is officially bilingual with localization laws requir…
> And navigation on Android / Google Maps can't pronounce French names for streets/places while driving around in bilingual places in Canada. Honestly, I think this is the right approach, and I'm speaking as a bilingual French/English speaker. Google Maps doesn't know that you are bilingual. So it has two choices: pronounce words the "right" (i.e., native) way, or pronounce them the "English" way. If someone who is u…
On the old lines, they had what sounded like a native English speaker do the announcements of the upcoming station, including the station name. On the newer ones it sounds like they just recorded the "we're arriving at" bit once and then spliced in the read-by-a-Chinese station name, which is much harder to understand as a foreigner. So on the new lines I was constantly staring at the displays.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#104Earlier quoted context omitted.
"I wonder how this kind of thing is organised, since there's all these jurisdictions." In theory simple. Crowdstrike is doing buisness in state X, so compensation claims will be settled in court in state X. So lots of courts and lawers all around the world, will be quite busy for some time with the case.
It's a B2B tool, which means it's quite likely the contract/license states that all disputes are to be settled in a court appointed by them. This is not valid for consumer disputes, but businesses are free to do what they want. Perhaps this will let them off the hook? OVH is different in that it's actually a French company.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#105Earlier quoted context omitted.
When working for a large US company they insisted we do not accept returns, they always were astonished that in Germany there is a law for 14 day returns, no questions asked. They could not understand that this is a law in Germany.
Isn’t it 60 days in the whole EU for physical objects bought via internet?
https://europa.eu/youreurope/citizens/consumers/shopping/gua...
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#106*might be liable And if France comes down hard on them, they may simply not do business in France.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#107Earlier quoted context omitted.
"I wonder how this kind of thing is organised, since there's all these jurisdictions." In theory simple. Crowdstrike is doing buisness in state X, so compensation claims will be settled in court in state X. So lots of courts and lawers all around the world, will be quite busy for some time with the case.
It's a B2B tool, which means it's quite likely the contract/license states that all disputes are to be settled in a court appointed by them. This is not valid for consumer disputes, but businesses are free to do what they want. Perhaps this will let them off the hook? OVH is different in that it's actually a French company.
In the end probably only the us companies will be left empty-handed.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#108It's good to remind people that general liability waivers you often find with license agreements have no meaning outside of US jurisdiction if you're doing business in another jurisdiction.
The number of US tech businesses that are surprised they need, or think they can ignore the need, to obey employment and data protection laws when working in other jurisdictions is simply bonkers.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#109Earlier quoted context omitted.
It's not unusual in the US to assume the US are the only planet in the universe.
Special mention of the expression “the west” which Americans like to use to mean the USA and some amorphous blob I don’t really want to think about but I’m going to pretend is exactly the same as the USA.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#110In the OVH case, their backup system (as a whole) failed. Many customers were left with 0 data, and per the article "the court ruled the OVH backup service was not operated to a reasonable standard and failed at its purpose".
Meanwhile CrowdStrike "just" crashed their customer's kernels, for a duration of about 1 hour (during which they were 100% safe from cyber attacks!). Any remaining delays getting systems back online were (in my view) due to customers not having good enough disaster recovery plans. There's certainly grounds to argue that CrowdStrike's software was "not to a reasonable standard", but the first-order impacts (a software crash) are of a very different magnitude to permanently losing all data in a literal ball of fire (as in the OVH case).
Software crashes all the time. For better or for worse, we treat software bugs as an inevitability in most industries (there are exceptions, of course). While software bugs are the "fault" of the software vendor, the job of mitigating the impacts thereof lies with the people deploying it. The only thing that makes the CrowdStrike case newsworthy, compared to all the other software crashes that happen on a daily basis, is that CrowdStrike's many customers had inserted their software into many critical pathways.
CrowdStrike sells a playing card, and customers collectively built a house with them.
(P.S. Don't treat this as a defense of CrowdStrike. I think their software sucks and was developed sloppily. I think they should face consequences for their sloppiness, I just don't think they will, under current legal frameworks. At best, maybe people will vote with their wallets, going forwards.)