Live data from Hacker News

CrowdStrike will be liable for damages in France, based on the OVH precedent

thehftguy.com

181–190 of 285 posts

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#181

Earlier quoted context omitted.

> Just look at the recent Boeing incident where people were killed, the company clearly misled the US authorities and settled only a $0.5B fine. The problem is when you fine a company, they will just turn around and offload that cost to their customers. Which in this case is the US government in a very large way. Boeing will make their part in the SLS a few billion more expensive again to offset it and even gain some…

That only works when the company has full power to set prices unilaterally, i.e. when it has monopoly power. Which is a separate problem that should be prevented separately. If Cisco gets fined a billion dollars, it can't just hike up the price of a router, as it will lose plenty of business to Juniper/Arista/F5/etc.

They can in the short term because they have tons of companies way too invested in their ecosystem to change.

See what VMWare did after the broadcom takeover. They did exactly that.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#182

French here, and working for another french CSP. We lived the OVH incident live and saw the whole aftermath. OVH was held liable because of the data loss, not for the service interruption. Data loss is something irremediable, permanent, definitive. Some businesses were basically ruined from this incident because they had no more data to operate. To add insult to injury, they sold offsite backups in the datacenter lit…

IMHO it would send really wrong signals if this doesn't end up with CrowdStrike closing their doors... like if the largest outage in history was caused by you due to a config parser failing and it looks as far as I can tell that they didn't follow industry best practices when it comes to config/parsing handling and probably also didn't follow some best practices when it comes to kernel module programming then honestl…

> it would send really wrong signals if this doesn't end up with CrowdStrike closing their doors

I thought the same until I saw the damage estimates. They’re in the single-digit billions. That’s well below CrowdStrike’s market cap. Unless we’re going hard for retributive justice, liability should be enough.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#183

Can someone explain to me why the protections that Falcon provides, are not provided by the OS itself? I am not completely naive, I've secured quite a few critical Linux servers, but with Windows it seems that there do not exist the same clear roles of security. Contrast with Red Hat or even Canonical, where is feels like I'm (correctly) fighting the security of the systems to get them into a state where my users can…

There are 2 possible questions. (1) - Why is a crutch like "anti-virus" software needed? Essentially trying to reactively cat-and-mouse hostile software that the OS has let execute on the computer. (2) Why doesn't Windows provide AV? Question (1) is more interesting - and (2) is addressed by other comments. I think both MS and their customers have very seldom prioritized security over even small compromises in functi…

The cat-and-mouse game is between OS security features and hackers. AV software is not a crutch, it's an extra level of defense. All OS kernels are vulnerable to malware - this is a 100% given at this moment in history. The question is how to mitigate this problem, and AV is one component of that, as are firewalls, network-level intrusion prevention systems, and a whole host of other security software.

Maybe some day someone will write an OS that is "fully secure" and then they'll be able to confidently run a system whose users can confidently click a link in an email, download an .exe from there, and run it, without fear of losing or leaking a single bit of data. That day is definitely not here, and until then, we all do the best we can through education and security appliances.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#184
post #33

Earlier quoted context omitted.

Well, it'd be a lot easier if most US entities understood that M/d/yy(yy) format is rare, or that default to Frankenstein degrees is pretty much the same/awkward (even Microsoft reset their weather widget to F on regular basis). The root of issue, not understanding local laws/culture, is very similar - surrounded by a vast market/culture (US +Canada) dulls your senses for the rest of the globe.

> surrounded by a vast market/culture (US +Canada) US companies don't think about Canada as anything but an afterthought, and struggle with the same issues here that you just mentioned. Canada is metric, uses different spellings (closer to UK English.. colour, not color [Chrome just marked my spelling as wrong despite me having Canadian English as my setting]) and is officially bilingual with localization laws requir…

The spelling of +Canada is very much on purpose (no space). I am very much aware Canada is metric and bilingual.

Due to the proximity of US (tooling/documentation), lots of the trades still operate in non-metric (or some unholy combo). Most folks would be a lot more familiar of PSI when it comes to tyre pressure (compared to bars), etc. I don't know if L/100km is the standard unit to measure fuel consumption (efficiency).

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#185

Earlier quoted context omitted.

> surrounded by a vast market/culture (US +Canada) US companies don't think about Canada as anything but an afterthought, and struggle with the same issues here that you just mentioned. Canada is metric, uses different spellings (closer to UK English.. colour, not color [Chrome just marked my spelling as wrong despite me having Canadian English as my setting]) and is officially bilingual with localization laws requir…

> And navigation on Android / Google Maps can't pronounce French names for streets/places while driving around in bilingual places in Canada. Honestly, I think this is the right approach, and I'm speaking as a bilingual French/English speaker. Google Maps doesn't know that you are bilingual. So it has two choices: pronounce words the "right" (i.e., native) way, or pronounce them the "English" way. If someone who is u…

>Google Maps doesn't know that you are bilingual.

But it does know, e.g. "Accept-Language" header. Of course, google resent that part and travelling across Europe results in having a different language every day.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#186
post #33

Earlier quoted context omitted.

Well, it'd be a lot easier if most US entities understood that M/d/yy(yy) format is rare, or that default to Frankenstein degrees is pretty much the same/awkward (even Microsoft reset their weather widget to F on regular basis). The root of issue, not understanding local laws/culture, is very similar - surrounded by a vast market/culture (US +Canada) dulls your senses for the rest of the globe.

I am not sure it's fair to include Canada in the same basket. We don't use freedom degrees, we know that numbers should start with the most significant digits and I believe liability waivers have no value here as well.

I did respond to another comment. The punctuation was very much on purpose, "+Canada", w/o the leading space to denote that there is a separation.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#187

Earlier quoted context omitted.

How is it someone other than CrowdStrike's fault that the systems failed again at every reboot until someone with physical access and know-how deleted the crashing driver manually from recovery mode? What should a company operating, say, an MRI machine protected by CrowdStrike have done to recover access in a reasonable amount of time?

CrowdStrike's software should not be installed on an MRI machine, per CrowdStrike's own guidance: "Neither the offerings nor crowdstrike tools are for use in the operation of [...] direct or indirect life-support systems [...] or any application or installation where failure could result in death, severe physical injury, or property damage." https://www.crowdstrike.com/terms-conditions/

If the PC controlling an MRI crashes nothing will happen to the instrument itself. The data might be lost and you can't continue using the MRI until this is fixed, but not more. This would not violate these guidelines.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#188
post #184

Earlier quoted context omitted.

> surrounded by a vast market/culture (US +Canada) US companies don't think about Canada as anything but an afterthought, and struggle with the same issues here that you just mentioned. Canada is metric, uses different spellings (closer to UK English.. colour, not color [Chrome just marked my spelling as wrong despite me having Canadian English as my setting]) and is officially bilingual with localization laws requir…

The spelling of +Canada is very much on purpose (no space). I am very much aware Canada is metric and bilingual. Due to the proximity of US (tooling/documentation), lots of the trades still operate in non-metric (or some unholy combo). Most folks would be a lot more familiar of PSI when it comes to tyre pressure (compared to bars), etc. I don't know if L/100km is the standard unit to measure fuel consumption (efficie…

L/100km is standard, especially because our roads use km measurements. I use both KPa and PSI. Measure my personal weight in pounds, but doctor and etc work in kg. Trades people work in both, by necessity. (My father was a machinist / tool&die maker who trained in Germany... drove him nuts).

It's just the reality of "sleeping with the elephant" as the expression goes here. We just have it worse than Europe.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#189
post #70

Earlier quoted context omitted.

How do you actively detect a malware agent running in user space using stealth or a kernel. Authors of such are fully aware of Linux hardening like SELinux / AppArmor and work around it.

> How do you actively detect a malware agent running in user space using stealth or a kernel. You start with correct design. The system has a root of trust (ideally you skip the insane level of complexity that is Secure Boot + TPM and use something simple, testable, and verifiable — this isn’t actually that hard). Only authorized images will boot, and, more importantly, nothing else on the network trusts the machine…

You haven't answered anything interesting. Any software system that anyone cares about operates on state - user documents, a database, other bespoke systems etc. If the operator of that system accidentally deploys malware to it, how to you ensure that this malware doesn't destroy, replace, or exfiltrate this state the the system normally operates on?

Malicious code doesn't need to run as root in order to completely destroy a business.

Not to mention, all of the things you describe are very nice if the kernel is perfectly secure. But it's not, so it's always possible and even likely that compromising any user on the system is equivalent to compromising root. And if you compromise one system, you can then exploit bugs in other systems' kernels that might allow RCE through well-crafted packets or other exploits that gain access without running through any user-space code that might validate those attestations.

And finally, when a vulnerability is found allowing such exploits, you now need to update all of these readonly systems - and this happens at least once a month. Do you go with a USB stick to each of 10k systems on five continents to update them?

This kind of smug "I know better than the rest of the industry, security is easy if you do things my way" is rarely productive or applicable.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#190

Earlier quoted context omitted.

How do you actively detect a malware agent running in user space using stealth or a kernel. Authors of such are fully aware of Linux hardening like SELinux / AppArmor and work around it.

> How do you actively detect a malware agent running in user space using stealth Depending how advanced the attacker is, check the executing binary maps back to the actual expected name and location on disk. Make sure the executable and libraries used at runtime are the correct ones matching hashes of known good qualities. Ensure the process tree structure has an expected structure, ie "bash" isnt starting a process…

Who collects and maintains all these lists of known good/expected configurations? Should the kernel know that apache shouldn't be launched from root? How about autocad, is that ok to be launched from bash? What directories should autocad be reading/writing?
Post reply on HN