Live data from Hacker News

CrowdStrike will be liable for damages in France, based on the OVH precedent

thehftguy.com

151–160 of 285 posts

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#151

And yet there is no mention on the end-customers Change Management and Patch Management practices. Who pushes an update on 1000-5000-10000 machines without testing it? To whoever does this I have only one quote from Jaws: You go in the cage, cage goes in the water, you go in the water, shark's in the water, our shark. Farewell and adieu to you, fair Spanish ladies. Farewell and adieu, you ladies of Spain.

> Who pushes an update on 1000-5000-10000 machines without testing it?

No-one is seriously claiming CrowdStrike did that.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#152
post #117

Earlier quoted context omitted.

I acquainted with a guy at a conference in US and he was genuinely surprised I had no idea, how long US mile is. I explained him, we use metric system and his response was “but don’t you learn *the standard* system in ache school?” I did not know, how to respond.

> we use metric system and his response was “but don’t you learn *the standard* system in ache school?” I did not know, how to respond It’s just a difference in travel and seniority. If you aren’t talking across continents there is no need to speak two languages.

> If you aren’t talking across continents there is no need to speak two languages

Continents have nothing to do with this. If you live in the UK and need to talk to people in the USA and Australia, you can be monolingual and still speak with people in three continents. If you live in Switzerland, you may need to speak 3 languages just to be able to talk with all your neighbors.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#154
post #132

This headline is kind of misleading. It's actually someone's personal (educated) opinion on a blog, not a statement of fact. Should be something more like "I think CrowdStrike will be liable" or "CrowdStrike should be liable"

the full headline (at this time at least) is more nuanced than seen here in hn: CrowdStrike will be liable for damages in France, based on the OVH precedent.

It's also in the URL. Submitter, please don't remove important parts of headlines.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#155
not just in France

most(all?) EU have laws which limit how much you can opt out of liability _no matter what you write into a contract_

while I'm not sure about the exact boundaries per country but I'm pretty sure that at least all hospitals, emergency call services etc. can sue for a non-negligible part of the damages that outage caused directly

private people which where harmed by not getting operations done in time most likely can also sue them for the full damages caused to them (through it's hard to assess the damages and it might need to be indirectly by suing the hospital and the hospital sues for more damages)

what you likely will not be able to sue for is the lost opportunity cost, the man power needed to fix it etc.

also my guess is that for a lot of cases which are not as sever as human damages or as indirect as lost opportunity cost a huge factor will depend on the degree of negligence judges believe happened. And here "negligence" isn't limited to the specific change which caused the bug but also if they kept they due diligence in choices of tooling, approaches, business processes etc. to reasonable minimize the risk. (like e.g. was their way of parsing configs inadequate/did it follow industry best practices (IMHO it doesn't seem so), or was it adequate to mark the driver as required to allow boot (else windows would have auto disabled it and then restarted) etc.)

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#156

French here, and working for another french CSP. We lived the OVH incident live and saw the whole aftermath. OVH was held liable because of the data loss, not for the service interruption. Data loss is something irremediable, permanent, definitive. Some businesses were basically ruined from this incident because they had no more data to operate. To add insult to injury, they sold offsite backups in the datacenter lit…

If a business closed down because of the OVH incident, how were the damages calculated? 1x annual revenue? Profit? 5x?

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#157
post #91
post #62

Earlier quoted context omitted.

That's easy, it's the US and any Canadian city with an NHL team.

I'd argue the UK is part of "the west"?

The UK is the old west (but not the Old West).

London is in the global west, except for the whole thing with the Greenwich Meridian going through… Greenwich, east London. Not to be confused with East London, which is in South Africa, which fortunately is also in south Africa.

The UK is definitely in the west of Europe though.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#158

What is hilarious to me is how the US government or courts doesn't seem to give a shit about this. Corporativism in US is a thing. Companies can brick hospital systems killing patients, drive self-driving cars and run over people but don't get sued, and if they do, they settle for very little. Just look at the recent Boeing incident where people were killed, the company clearly misled the US authorities and settled o…

> Just look at the recent Boeing incident where people were killed, the company clearly misled the US authorities and settled only a $0.5B fine. The problem is when you fine a company, they will just turn around and offload that cost to their customers. Which in this case is the US government in a very large way. Boeing will make their part in the SLS a few billion more expensive again to offset it and even gain some…

That only works when the company has full power to set prices unilaterally, i.e. when it has monopoly power. Which is a separate problem that should be prevented separately. If Cisco gets fined a billion dollars, it can't just hike up the price of a router, as it will lose plenty of business to Juniper/Arista/F5/etc.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#159

French here, and working for another french CSP. We lived the OVH incident live and saw the whole aftermath. OVH was held liable because of the data loss, not for the service interruption. Data loss is something irremediable, permanent, definitive. Some businesses were basically ruined from this incident because they had no more data to operate. To add insult to injury, they sold offsite backups in the datacenter lit…

IMHO it would send really wrong signals if this doesn't end up with CrowdStrike closing their doors...

like if the largest outage in history was caused by you due to a config parser failing and it looks as far as I can tell that they didn't follow industry best practices when it comes to config/parsing handling and probably also didn't follow some best practices when it comes to kernel module programming then honestly it would be really strange if you didn't had to declare bankruptcy due to damage payments (which doesn't mean the software is now gone/unmaintained, there are a lot of ways to make sure that doesn't happen, e.g. MS anyway had interest in buying Falcon).

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#160

Earlier quoted context omitted.

That would mean that you always need a fully redundant copy of everything based on entirely different OSes and software with no common component. That is obviously not realistic.

No. You just need to not update them all at the same time.

Unfortunately, CrowdStrike decides when it's time to upgrade CrowdStrike software, not the admins.
Post reply on HN