Live data from Hacker News

CrowdStrike will be liable for damages in France, based on the OVH precedent

thehftguy.com

121–130 of 285 posts

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#121

What is hilarious to me is how the US government or courts doesn't seem to give a shit about this. Corporativism in US is a thing. Companies can brick hospital systems killing patients, drive self-driving cars and run over people but don't get sued, and if they do, they settle for very little. Just look at the recent Boeing incident where people were killed, the company clearly misled the US authorities and settled o…

I think you meant US companies. The fine for Volkswagen was $20B+.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#122
post #40

Can someone explain to me why the protections that Falcon provides, are not provided by the OS itself? I am not completely naive, I've secured quite a few critical Linux servers, but with Windows it seems that there do not exist the same clear roles of security. Contrast with Red Hat or even Canonical, where is feels like I'm (correctly) fighting the security of the systems to get them into a state where my users can…

Windows does have Defender, which does some amount of tracking signatures and heuristics of various types of malware. It has not, however, proved enough to fend off different real world problems like ransomware. Hence, the market for 3rd party solutions that are more aggressive. And to keep up with real world threats, they have to update often. And have to run at high privilege levels. So now you have the situation w…

Microsoft has a high share in this area but enterprise security is generally a very competivite market. Microsoft may even move into #1 position as a fallout from this debacle becasue the market share between them and the #1 CS is very small (that does not mean people actually buy more Ms btw... if that needs to be said ;)

This is not neccesarily a good thing for MSFT as it will 100% trigger regulator rage in the EU.

https://www.statista.com/statistics/917405/worldwide-enterpr...

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#123
post #101

What is hilarious to me is how the US government or courts doesn't seem to give a shit about this. Corporativism in US is a thing. Companies can brick hospital systems killing patients, drive self-driving cars and run over people but don't get sued, and if they do, they settle for very little. Just look at the recent Boeing incident where people were killed, the company clearly misled the US authorities and settled o…

what if the fine was giving up some shares to the government? With such a rule, after enough fines, the company would basically automatically become a public company.

[dead]

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#124

I'm not a lawyer, and I'm definitely not a French lawyer, but I don't think the OVH comparison is valid. In the OVH case, their backup system (as a whole) failed. Many customers were left with 0 data, and per the article "the court ruled the OVH backup service was not operated to a reasonable standard and failed at its purpose". Meanwhile CrowdStrike "just" crashed their customer's kernels, for a duration of about 1…

It didn't just crash, it crashed 100% of computers running it at that time and in a way that required physical intervention to fix. So I think you can considers this quite different from regular crashes because recovery is much more difficult and because it affected a lot of computers simultaneously.

On top of that there are companies that had failures of their own in their recovery procedures. But even with good procedures this can be a significant outage because it is not trivially reverted and would typically affect many configurations that are redundant for many other failures.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#125
post #117
post #33

Earlier quoted context omitted.

Well, it'd be a lot easier if most US entities understood that M/d/yy(yy) format is rare, or that default to Frankenstein degrees is pretty much the same/awkward (even Microsoft reset their weather widget to F on regular basis). The root of issue, not understanding local laws/culture, is very similar - surrounded by a vast market/culture (US +Canada) dulls your senses for the rest of the globe.

I acquainted with a guy at a conference in US and he was genuinely surprised I had no idea, how long US mile is. I explained him, we use metric system and his response was “but don’t you learn *the standard* system in ache school?” I did not know, how to respond.

> we use metric system and his response was “but don’t you learn *the standard* system in ache school?” I did not know, how to respond

It’s just a difference in travel and seniority. If you aren’t talking across continents there is no need to speak two languages.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#126
post #20

Earlier quoted context omitted.

The number of US tech businesses that are surprised they need, or think they can ignore the need, to obey employment and data protection laws when working in other jurisdictions is simply bonkers.

It's not unusual in the US to assume the US are the only planet in the universe.

> not unusual in the US to assume the US are the only planet in the universe

This is true for every large culture.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#127

Earlier quoted context omitted.

Isn’t it 60 days in the whole EU for physical objects bought via internet?

14 days - 1 year of repairs if you didn't break it https://europa.eu/youreurope/citizens/consumers/shopping/gua...

Thanks for the link!

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#128

I'm not a lawyer, and I'm definitely not a French lawyer, but I don't think the OVH comparison is valid. In the OVH case, their backup system (as a whole) failed. Many customers were left with 0 data, and per the article "the court ruled the OVH backup service was not operated to a reasonable standard and failed at its purpose". Meanwhile CrowdStrike "just" crashed their customer's kernels, for a duration of about 1…

It didn't just crash, it crashed 100% of computers running it at that time and in a way that required physical intervention to fix. So I think you can considers this quite different from regular crashes because recovery is much more difficult and because it affected a lot of computers simultaneously. On top of that there are companies that had failures of their own in their recovery procedures. But even with good pro…

If the uptime of 100% of your computers depends on a single vendor not writing software with bugs in it, you have a problem.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#129

I'm not a lawyer, and I'm definitely not a French lawyer, but I don't think the OVH comparison is valid. In the OVH case, their backup system (as a whole) failed. Many customers were left with 0 data, and per the article "the court ruled the OVH backup service was not operated to a reasonable standard and failed at its purpose". Meanwhile CrowdStrike "just" crashed their customer's kernels, for a duration of about 1…

> for a duration of about 1 hour

Not even remotely correct.

Most computers that were affected by the fault needed physical remediation via safe mode boot to fix the issue because they were not able to download a fix because of being stuck in a reboot loop. The understanding is that for most cases, the fix needed to be applied by an IT technician dispatched to physically access the computer.

A week or 168 hours later, there are still many, many computers out there that remain bricked by this fault because it is so heinously difficult to fix.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#130

What is hilarious to me is how the US government or courts doesn't seem to give a shit about this. Corporativism in US is a thing. Companies can brick hospital systems killing patients, drive self-driving cars and run over people but don't get sued, and if they do, they settle for very little. Just look at the recent Boeing incident where people were killed, the company clearly misled the US authorities and settled o…

> Just look at the recent Boeing incident where people were killed, the company clearly misled the US authorities and settled only a $0.5B fine.

The problem is when you fine a company, they will just turn around and offload that cost to their customers. Which in this case is the US government in a very large way. Boeing will make their part in the SLS a few billion more expensive again to offset it and even gain some profit. The US government are just fining themselves.

Fines just aren't an effective deterrent for companies. They should go back to imposing personal sentences on their leadership. But this is really unpopular because these guys are so well connected. So basically nothing is done and everyone goes free.

Post reply on HN