CrowdStrike will be liable for damages in France, based on the OVH precedent
161–170 of 285 posts
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#162Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#163What is hilarious to me is how the US government or courts doesn't seem to give a shit about this. Corporativism in US is a thing. Companies can brick hospital systems killing patients, drive self-driving cars and run over people but don't get sued, and if they do, they settle for very little. Just look at the recent Boeing incident where people were killed, the company clearly misled the US authorities and settled o…
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#164What is hilarious to me is how the US government or courts doesn't seem to give a shit about this. Corporativism in US is a thing. Companies can brick hospital systems killing patients, drive self-driving cars and run over people but don't get sued, and if they do, they settle for very little. Just look at the recent Boeing incident where people were killed, the company clearly misled the US authorities and settled o…
> Just look at the recent Boeing incident where people were killed, the company clearly misled the US authorities and settled only a $0.5B fine. The problem is when you fine a company, they will just turn around and offload that cost to their customers. Which in this case is the US government in a very large way. Boeing will make their part in the SLS a few billion more expensive again to offset it and even gain some…
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#165Earlier quoted context omitted.
> for a duration of about 1 hour Not even remotely correct. Most computers that were affected by the fault needed physical remediation via safe mode boot to fix the issue because they were not able to download a fix because of being stuck in a reboot loop. The understanding is that for most cases, the fix needed to be applied by an IT technician dispatched to physically access the computer. A week or 168 hours later,…
See the sentence I wrote just after that one.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#166Can someone explain to me why the protections that Falcon provides, are not provided by the OS itself? I am not completely naive, I've secured quite a few critical Linux servers, but with Windows it seems that there do not exist the same clear roles of security. Contrast with Red Hat or even Canonical, where is feels like I'm (correctly) fighting the security of the systems to get them into a state where my users can…
(1) - Why is a crutch like "anti-virus" software needed? Essentially trying to reactively cat-and-mouse hostile software that the OS has let execute on the computer.
(2) Why doesn't Windows provide AV?
Question (1) is more interesting - and (2) is addressed by other comments.
I think both MS and their customers have very seldom prioritized security over even small compromises in functionality. We loudly blame MS but they are the vendor MS customers deserve. While it's not a democracy, there are parallels to the popular sport of blaming politicians for eg not doing hard choices against climate change while holding the voters innocent.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#167Earlier quoted context omitted.
It didn't just crash, it crashed 100% of computers running it at that time and in a way that required physical intervention to fix. So I think you can considers this quite different from regular crashes because recovery is much more difficult and because it affected a lot of computers simultaneously. On top of that there are companies that had failures of their own in their recovery procedures. But even with good pro…
If the uptime of 100% of your computers depends on a single vendor not writing software with bugs in it, you have a problem.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#168This article feels like it was written or augmented with an LLM.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#169Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#170I'm not a lawyer, and I'm definitely not a French lawyer, but I don't think the OVH comparison is valid. In the OVH case, their backup system (as a whole) failed. Many customers were left with 0 data, and per the article "the court ruled the OVH backup service was not operated to a reasonable standard and failed at its purpose". Meanwhile CrowdStrike "just" crashed their customer's kernels, for a duration of about 1…
> for a duration of about 1 hour Not even remotely correct. Most computers that were affected by the fault needed physical remediation via safe mode boot to fix the issue because they were not able to download a fix because of being stuck in a reboot loop. The understanding is that for most cases, the fix needed to be applied by an IT technician dispatched to physically access the computer. A week or 168 hours later,…
I could imagine this was not the case if you had to physically access remote servers, or didn’t have access to bit locker recovery keys