Live data from Hacker News

CrowdStrike will be liable for damages in France, based on the OVH precedent

thehftguy.com

161–170 of 285 posts

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#163

What is hilarious to me is how the US government or courts doesn't seem to give a shit about this. Corporativism in US is a thing. Companies can brick hospital systems killing patients, drive self-driving cars and run over people but don't get sued, and if they do, they settle for very little. Just look at the recent Boeing incident where people were killed, the company clearly misled the US authorities and settled o…

[deleted]

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#164

What is hilarious to me is how the US government or courts doesn't seem to give a shit about this. Corporativism in US is a thing. Companies can brick hospital systems killing patients, drive self-driving cars and run over people but don't get sued, and if they do, they settle for very little. Just look at the recent Boeing incident where people were killed, the company clearly misled the US authorities and settled o…

> Just look at the recent Boeing incident where people were killed, the company clearly misled the US authorities and settled only a $0.5B fine. The problem is when you fine a company, they will just turn around and offload that cost to their customers. Which in this case is the US government in a very large way. Boeing will make their part in the SLS a few billion more expensive again to offset it and even gain some…

The problem here is that "the company" is liable for the negligence of the person in charge. The person in charge is not liable for anything. And like you said, if the company has to pay, then the money obviously comes from its customers, not from the person in charge.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#165

Earlier quoted context omitted.

> for a duration of about 1 hour Not even remotely correct. Most computers that were affected by the fault needed physical remediation via safe mode boot to fix the issue because they were not able to download a fix because of being stuck in a reboot loop. The understanding is that for most cases, the fix needed to be applied by an IT technician dispatched to physically access the computer. A week or 168 hours later,…

See the sentence I wrote just after that one.

How is it someone other than CrowdStrike's fault that the systems failed again at every reboot until someone with physical access and know-how deleted the crashing driver manually from recovery mode? What should a company operating, say, an MRI machine protected by CrowdStrike have done to recover access in a reasonable amount of time?

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#166

Can someone explain to me why the protections that Falcon provides, are not provided by the OS itself? I am not completely naive, I've secured quite a few critical Linux servers, but with Windows it seems that there do not exist the same clear roles of security. Contrast with Red Hat or even Canonical, where is feels like I'm (correctly) fighting the security of the systems to get them into a state where my users can…

There are 2 possible questions.

(1) - Why is a crutch like "anti-virus" software needed? Essentially trying to reactively cat-and-mouse hostile software that the OS has let execute on the computer.

(2) Why doesn't Windows provide AV?

Question (1) is more interesting - and (2) is addressed by other comments.

I think both MS and their customers have very seldom prioritized security over even small compromises in functionality. We loudly blame MS but they are the vendor MS customers deserve. While it's not a democracy, there are parallels to the popular sport of blaming politicians for eg not doing hard choices against climate change while holding the voters innocent.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#167

Earlier quoted context omitted.

It didn't just crash, it crashed 100% of computers running it at that time and in a way that required physical intervention to fix. So I think you can considers this quite different from regular crashes because recovery is much more difficult and because it affected a lot of computers simultaneously. On top of that there are companies that had failures of their own in their recovery procedures. But even with good pro…

If the uptime of 100% of your computers depends on a single vendor not writing software with bugs in it, you have a problem.

What if the uptime of 50% of your computers does, but you need 100% percent of your computers to run at 100% capacity? If a shop has two lathes and one crashes, and now the shop has 50% capacity, is not losing money because of CrowdStrike's incompetence?

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#169

Earlier quoted context omitted.

But randsomware is mostly targeted to servers, many of the devices affected were clients

Is it? I think ransomware affects clients more than servers, doesn't it?

Yes, or rather, it creeps into systems through workstation clients.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#170

I'm not a lawyer, and I'm definitely not a French lawyer, but I don't think the OVH comparison is valid. In the OVH case, their backup system (as a whole) failed. Many customers were left with 0 data, and per the article "the court ruled the OVH backup service was not operated to a reasonable standard and failed at its purpose". Meanwhile CrowdStrike "just" crashed their customer's kernels, for a duration of about 1…

> for a duration of about 1 hour Not even remotely correct. Most computers that were affected by the fault needed physical remediation via safe mode boot to fix the issue because they were not able to download a fix because of being stuck in a reboot loop. The understanding is that for most cases, the fix needed to be applied by an IT technician dispatched to physically access the computer. A week or 168 hours later,…

For what it’s worth - I got the BSOD, once I got the email from IT with the instructions, it took me about 20min to apply the fix. Almost all of the company employees who were affected were able to easily apply a self help fix.

I could imagine this was not the case if you had to physically access remote servers, or didn’t have access to bit locker recovery keys

Post reply on HN