Live data from Hacker News

CrowdStrike will be liable for damages in France, based on the OVH precedent

thehftguy.com

111–120 of 285 posts

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#111

Earlier quoted context omitted.

Isn’t it 60 days in the whole EU for physical objects bought via internet?

14 days - 1 year of repairs if you didn't break it https://europa.eu/youreurope/citizens/consumers/shopping/gua...

Yes, IMHO the German law was earlier.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#112
post #37

Earlier quoted context omitted.

EDRs are the devil's spyware. Especially since corporate "security" people are now pushing for EDRs to run on Linux. Argument is that the cloud nature of the thing makes it necessary that it runs everywhere. Fact is, since my company forced me to install this black box, my system is definitely less secure. Before that, I didnt have a single incoming port enabled. Now, my system talks to all sorts of external things w…

If your system was processing any valuable information owned by the company (code, PII, etc) than the company is likely much safer today than it was when you had exclusive control over that system, even if they introduced several vulnerabilities. Previously, if you decided/were coerced to do something against the company's interests, you could do whatever you wanted from that system and they never would have even kno…

Well, now we're getting somewhere. If my company distrusts me so much that it needs to put a black box in place to prevent me from fucking it over, it shouldn't hire me as an admin for tons and tons of infrastructure. Distrust goes both ways. Increase the pressure, and maybe, maybe, your employee will just leave for another company that doesn't behave that way (yet). The timing is great, because some employees still remember how they were treated during 2020/21.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#113
post #76
post #51

Earlier quoted context omitted.

"I wonder how this kind of thing is organised, since there's all these jurisdictions." In theory simple. Crowdstrike is doing buisness in state X, so compensation claims will be settled in court in state X. So lots of courts and lawers all around the world, will be quite busy for some time with the case.

It's a B2B tool, which means it's quite likely the contract/license states that all disputes are to be settled in a court appointed by them. This is not valid for consumer disputes, but businesses are free to do what they want. Perhaps this will let them off the hook? OVH is different in that it's actually a French company.

> It's a B2B tool, which means it's quite likely the contract/license states that all disputes are to be settled in a court appointed by them.

Many businesses will simply refuse to buy your product if the contract says the dispute has to be settled under foreign law or by a foreign court. The customer's lawyers will flag such a term as an unacceptable legal risk. And if your competitor isn't demanding that term, you are giving them a big reason to choose the competitor instead.

Random example: Oracle's standard contracts with their Australian customers says disputes will be settled under Australian law (New South Wales state law) in an Australian court (in Sydney). [0] And Oracle's standard agreements for France nominate French law and the courts of Paris. [1]

If Oracle can't get away with forcing foreign law/courts on their customers, I'd be surprised if CrowdStrike can.

Might be a different story for smaller countries, but most businesses in major economies are used to vendors offering contracts under their own national law.

[0] for example https://www.oracle.com/us/corporate/contracts/cloud-csa-v012... – see clause 14 on page 7

[1] for example https://www.oracle.com/assets/cloud-csa-v012418-fr-eng-44198... – see clause 14 on page 6

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#114
post #30

> Does CrowdStrike do any testing whatsoever? Obviously they didn’t or the incident wouldn’t have happened. Eh, parts of this article aren't very reasonable. Even if they did a buttload of testing, it only takes one failure in one part of the chain (near the end). They didn't test something they should have, sure, but obviously they didn't do "no testing whatsoever"

Deploying untested changes isn't "near the end of the chain", and it voids any buttload of testing of something else.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#115
post #101

What is hilarious to me is how the US government or courts doesn't seem to give a shit about this. Corporativism in US is a thing. Companies can brick hospital systems killing patients, drive self-driving cars and run over people but don't get sued, and if they do, they settle for very little. Just look at the recent Boeing incident where people were killed, the company clearly misled the US authorities and settled o…

what if the fine was giving up some shares to the government? With such a rule, after enough fines, the company would basically automatically become a public company.

Sounds too much like socialism to go anyhere.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#116
post #9

I was aware of this being the case when dealing with consumers, but had assumed that because B2B contracts are assumed to be between 2 sophisticated parties that there is little legislative protection that could override the terms of the contract. My understanding of law is generally UK based, but I'm not aware of legislation what would supersede a contract term limiting liability when the event that created the liab…

I think the general idea is that gross negligence is a breach of contract. Every contract implicitly assumes that both parties are making a good faith effort to honor the terms of the contract. If you are not doing that, you may be in breach of contract, and the liability limitations may no longer apply.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#117
post #33
post #20

Earlier quoted context omitted.

The number of US tech businesses that are surprised they need, or think they can ignore the need, to obey employment and data protection laws when working in other jurisdictions is simply bonkers.

Well, it'd be a lot easier if most US entities understood that M/d/yy(yy) format is rare, or that default to Frankenstein degrees is pretty much the same/awkward (even Microsoft reset their weather widget to F on regular basis). The root of issue, not understanding local laws/culture, is very similar - surrounded by a vast market/culture (US +Canada) dulls your senses for the rest of the globe.

I acquainted with a guy at a conference in US and he was genuinely surprised I had no idea, how long US mile is. I explained him, we use metric system and his response was “but don’t you learn *the standard* system in ache school?” I did not know, how to respond.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#119
I'm actually surprised the damage value I'm hearing about is not even $10B , I guess most of the downtime was on the weekend, but such a large scale 1-3 business day outage I'd think would a lot more. or perhaps it is because most small and medium businesses don't have crowdstrike because it is too expensive and they were not affected. Or another reason might be, indirect losses like the impact of delayed flights on individuals is not being considered.

I think if the total liability for Crowdstrike is less than a few years worth of revenue, they'll come out unscathed because as I understand, they are still not profitable, their valuation is purely on speculation on future revenue. Their biggest paying customers still care a lot about getting compromised, it isn't just a box checking exercise like many have suggested.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#120
post #101

What is hilarious to me is how the US government or courts doesn't seem to give a shit about this. Corporativism in US is a thing. Companies can brick hospital systems killing patients, drive self-driving cars and run over people but don't get sued, and if they do, they settle for very little. Just look at the recent Boeing incident where people were killed, the company clearly misled the US authorities and settled o…

what if the fine was giving up some shares to the government? With such a rule, after enough fines, the company would basically automatically become a public company.

> what if the fine was giving up some shares to the government?

What is the advantage over just fining? We keep trying to reïnvent the fine, which is great for those who would otherwise be fined.

Post reply on HN