Earlier quoted context omitted.
> surrounded by a vast market/culture (US +Canada) US companies don't think about Canada as anything but an afterthought, and struggle with the same issues here that you just mentioned. Canada is metric, uses different spellings (closer to UK English.. colour, not color [Chrome just marked my spelling as wrong despite me having Canadian English as my setting]) and is officially bilingual with localization laws requir…
Google Nest prononciation of EN songs names in middle of sentence in other language was fun to ear. It’s been a wile it does pretty well (way better than at the beginning at least) so they probably have the tech to achieve street names prononciation.
CrowdStrike will be liable for damages in France, based on the OVH precedent
191–200 of 285 posts
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#192Can someone explain to me why the protections that Falcon provides, are not provided by the OS itself? I am not completely naive, I've secured quite a few critical Linux servers, but with Windows it seems that there do not exist the same clear roles of security. Contrast with Red Hat or even Canonical, where is feels like I'm (correctly) fighting the security of the systems to get them into a state where my users can…
Windows does have Defender, which does some amount of tracking signatures and heuristics of various types of malware. It has not, however, proved enough to fend off different real world problems like ransomware. Hence, the market for 3rd party solutions that are more aggressive. And to keep up with real world threats, they have to update often. And have to run at high privilege levels. So now you have the situation w…
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#193Earlier quoted context omitted.
> surrounded by a vast market/culture (US +Canada) US companies don't think about Canada as anything but an afterthought, and struggle with the same issues here that you just mentioned. Canada is metric, uses different spellings (closer to UK English.. colour, not color [Chrome just marked my spelling as wrong despite me having Canadian English as my setting]) and is officially bilingual with localization laws requir…
> And navigation on Android / Google Maps can't pronounce French names for streets/places while driving around in bilingual places in Canada. Honestly, I think this is the right approach, and I'm speaking as a bilingual French/English speaker. Google Maps doesn't know that you are bilingual. So it has two choices: pronounce words the "right" (i.e., native) way, or pronounce them the "English" way. If someone who is u…
I'm not bilingual but I'm British and the most irritating thing driving through France is hearing Google/Siri butcher French words. It makes it basically impossible to navigate!
I imagine most Brits would be able to hear a French word (spoken slowly enough) and recognise it written down.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#194Earlier quoted context omitted.
I am not sure it's fair to include Canada in the same basket. We don't use freedom degrees, we know that numbers should start with the most significant digits and I believe liability waivers have no value here as well.
> numbers should start with the most significant digits Am curious: where does that not happen in the US? (And in parts of Canada they say 4-20-10 to mean 90 :-)
It happens with dates and makes them unsortable.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#195Earlier quoted context omitted.
> If you aren’t talking across continents there is no need to speak two languages Continents have nothing to do with this. If you live in the UK and need to talk to people in the USA and Australia, you can be monolingual and still speak with people in three continents. If you live in Switzerland, you may need to speak 3 languages just to be able to talk with all your neighbors.
Languages as in knowing two systems. Sort of like how most people don’t need to know international date or thousands/decimal separator conventions, but those functioning internationally—whether due to being well travelled or senior enough to conduct international trade and/or relations—do. My going to a conference in India and arguing over the lakh/crore system isn’t useful to anyone [1]. [1] https://en.m.wikipedia.o…
And in Europe there are numerous differences between countries of this kind - Germans and a few others use different number separators (1,000 is 1000 in France or the UK or Spain, but 1 in Germany or Romania). Several places drive on opposite sides of the road. The UK uses many imperial units. I'm sure there are others I haven't even come across yet.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#196Earlier quoted context omitted.
No. You just need to not update them all at the same time.
Unfortunately, CrowdStrike decides when it's time to upgrade CrowdStrike software, not the admins.
2. Your IT department shouldn't buy a product that doesn't give you control on when updates are applied.
These are 2 huge security failures from your IT department.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#197Can someone explain to me why the protections that Falcon provides, are not provided by the OS itself? I am not completely naive, I've secured quite a few critical Linux servers, but with Windows it seems that there do not exist the same clear roles of security. Contrast with Red Hat or even Canonical, where is feels like I'm (correctly) fighting the security of the systems to get them into a state where my users can…
Actually, arguably Windows has some impressive security features unseen on any other mainstream OS, they're just not used by default and - realistically - would be hard to enable on general purpose / non-corporate computers. For example, by comparison, Linux is in the stone age here. Do you even need AV if untrusted code can't run in the first place? * Application whitelisting - with just bare old AppLocker, Windows…
I have always wondered about that; there has to be a more secure control method for those secrets.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#198Earlier quoted context omitted.
Well, it'd be a lot easier if most US entities understood that M/d/yy(yy) format is rare, or that default to Frankenstein degrees is pretty much the same/awkward (even Microsoft reset their weather widget to F on regular basis). The root of issue, not understanding local laws/culture, is very similar - surrounded by a vast market/culture (US +Canada) dulls your senses for the rest of the globe.
I acquainted with a guy at a conference in US and he was genuinely surprised I had no idea, how long US mile is. I explained him, we use metric system and his response was “but don’t you learn *the standard* system in ache school?” I did not know, how to respond.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#199Holy shit (hits the fan). For sure CrowdStrike will be held accountable in several countries, but I believe that some conclusions need to be drawn also from a customer/user perspective. - Is it reasonable to grant such privilege access to a piece of software that ultimately is a black box ? - Is it reasonable to put a Microsoft / Commercial / Closed source OS in critical infrastructure ? If not considered as critical…
Only your third point makes any sense. For the other two, obviously the answer is yes, that's entirely reasonable. Businesses and government organizations use plenty of commercial tools that they have no way of designing or understanding on their own. Software is no different from hardware from this point of view. A hospital doesn't have, and couldn't use even if it did, the blueprints for an MRI machine or an old-fa…
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#200Awesome. Falcon has been widely known (for years) as an utter piece of shit (code wise). Maybe now ClownStrike will start testing it properly, hopefully thereby fixing the stability and other issues.
Right, but other commenters call it the best EDR out there; so it is really hard for those of us outside the loop to understand what the hell is going on. Is CS, or any other EDR, actually preventing attacks that would pass through if absent? To what extent? Where are the numbers? Who audits CS code? I have seen no real data, only assertions.