Live data from Hacker News

CrowdStrike will be liable for damages in France, based on the OVH precedent

thehftguy.com

211–220 of 285 posts

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#211
post #202

Earlier quoted context omitted.

IMHO it would send really wrong signals if this doesn't end up with CrowdStrike closing their doors... like if the largest outage in history was caused by you due to a config parser failing and it looks as far as I can tell that they didn't follow industry best practices when it comes to config/parsing handling and probably also didn't follow some best practices when it comes to kernel module programming then honestl…

They didn't follow testing or deployment best practices either.

IIRC their QA team was impacted by the most recent round of layoffs. Dumping those responsibilities onto devs isn't a great solution to begin with, and especially not when the product is a complete trash fire.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#212
post #132

This headline is kind of misleading. It's actually someone's personal (educated) opinion on a blog, not a statement of fact. Should be something more like "I think CrowdStrike will be liable" or "CrowdStrike should be liable"

the full headline (at this time at least) is more nuanced than seen here in hn: CrowdStrike will be liable for damages in France, based on the OVH precedent.

Doesn’t really make it any less misleading. It is still just an opinion.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#213

Earlier quoted context omitted.

There are 2 possible questions. (1) - Why is a crutch like "anti-virus" software needed? Essentially trying to reactively cat-and-mouse hostile software that the OS has let execute on the computer. (2) Why doesn't Windows provide AV? Question (1) is more interesting - and (2) is addressed by other comments. I think both MS and their customers have very seldom prioritized security over even small compromises in functi…

The cat-and-mouse game is between OS security features and hackers. AV software is not a crutch, it's an extra level of defense. All OS kernels are vulnerable to malware - this is a 100% given at this moment in history. The question is how to mitigate this problem, and AV is one component of that, as are firewalls, network-level intrusion prevention systems, and a whole host of other security software. Maybe some day…

I don't want an OS that lets me run executables from email - I've never actually has to do that. I do want an OS that I can tell to run "Firefox, Anki, Thunderbird", once, and nothing else will run.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#214

Awesome. Falcon has been widely known (for years) as an utter piece of shit (code wise). Maybe now ClownStrike will start testing it properly, hopefully thereby fixing the stability and other issues.

> Awesome. Falcon has been widely known (for years) as an utter piece of shit (code wise). Right, but other commenters call it the best EDR out there; so it is really hard for those of us outside the loop to understand what the hell is going on. Is CS, or any other EDR, actually preventing attacks that would pass through if absent? To what extent? Where are the numbers? Who audits CS code? I have seen no real data, o…

Yeah, I'm as surprised as you that people have been saying ClownStrike Falcon was good.

I guess the people saying that are security folk who look at things from a high level place of some sort (?). Because they don't seem aware of (or don't care about) the many problems it causes on the servers it gets deployed to.

As we've now had amply demonstrated. Globally. ;)

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#215

Earlier quoted context omitted.

Languages as in knowing two systems. Sort of like how most people don’t need to know international date or thousands/decimal separator conventions, but those functioning internationally—whether due to being well travelled or senior enough to conduct international trade and/or relations—do. My going to a conference in India and arguing over the lakh/crore system isn’t useful to anyone [1]. [1] https://en.m.wikipedia.o…

Even then, continents have little to do with it. The Indian numbering system is indeed used in much of Asia - but it's not used in Russia for example. If you live in Vladivostok, you might need to learn these two systems even if you never do business with anyone farther than 300km from you. And in Europe there are numerous differences between countries of this kind - Germans and a few others use different number sepa…

> continents have little to do with it. The Indian numbering system is indeed used in much of Asia - but it's not used in Russia for example

Got it, you’re parsing continents literally. I was speaking colloquially. Read it as “cultures” in the first comment.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#216
post #20

Earlier quoted context omitted.

The number of US tech businesses that are surprised they need, or think they can ignore the need, to obey employment and data protection laws when working in other jurisdictions is simply bonkers.

When working for a large US company they insisted we do not accept returns, they always were astonished that in Germany there is a law for 14 day returns, no questions asked. They could not understand that this is a law in Germany.

What were they astonished at? The existence of such a law, or that they were subject to it?

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#217

Earlier quoted context omitted.

I think the mental model that security is attained by adding more security features just leads to sprawling complexity and awful things like AV. Secure operating system designs tend to simplify and take away stuff rather than add more bells and whistles.

Is there an example of a real OS for desktops and servers that is secure from this point of view? I think SeL4 might qualify, but that can only realistically be used for embedded applications, it doesn't have, at this time, many of the features you'd need to build, say, an HTTP API server for it.

I think the absence of real world usable secure alternatives is not really strong evidence, operating systems are like web browsers, there's such huge inertia and network effects in the apps that competition doesn't tend to spring up, "build it and they will come" doesn't work.

On the research side there's lots of stuff. Singularity, the various capability based systems, Qubes (granted more towards the adding-features dimension), etc.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#218

Earlier quoted context omitted.

Is there an example of a real OS for desktops and servers that is secure from this point of view? I think SeL4 might qualify, but that can only realistically be used for embedded applications, it doesn't have, at this time, many of the features you'd need to build, say, an HTTP API server for it.

I think the absence of real world usable secure alternatives is not really strong evidence, operating systems are like web browsers, there's such huge inertia and network effects in the apps that competition doesn't tend to spring up, "build it and they will come" doesn't work. On the research side there's lots of stuff. Singularity, the various capability based systems, Qubes (granted more towards the adding-feature…

I agree to some extent, but still: if you were starting your own company, would you wait until someone wrote a secure OS? Or would you provide your developers and sales people etc. with an existing OS, and run your servers on an existing OS, and deploy other security tools to mitigate the bugs in those existing OSs?

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#219

Earlier quoted context omitted.

Special mention of the expression “the west” which Americans like to use to mean the USA and some amorphous blob I don’t really want to think about but I’m going to pretend is exactly the same as the USA.

Somehow related, expressions like "next summer", "starting this spring" and such on public global announcements make absolutely nonsense if you are in the southern hemisphere (like a big percentage of the global population)

What are they supposed to use instead? "Starting in Q3/H2"?

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#220

French here, and working for another french CSP. We lived the OVH incident live and saw the whole aftermath. OVH was held liable because of the data loss, not for the service interruption. Data loss is something irremediable, permanent, definitive. Some businesses were basically ruined from this incident because they had no more data to operate. To add insult to injury, they sold offsite backups in the datacenter lit…

IMHO it would send really wrong signals if this doesn't end up with CrowdStrike closing their doors... like if the largest outage in history was caused by you due to a config parser failing and it looks as far as I can tell that they didn't follow industry best practices when it comes to config/parsing handling and probably also didn't follow some best practices when it comes to kernel module programming then honestl…

I don't understand why there is so much attention on the deployment and testing side of the coin. Yes, better testing and rollout strategy should have prevented this specific occurrence of a failure. But these strategies aren't bulletproof and things go wrong. You need defense in depth, and some responsibility has to lay on the consumer side for that to happen - particularly for fundamental humane industries like transportation and healthcare. These industries should not be allowed to run any software like this - privileged and without controlled rollouts. I'm all for shaming CrowdStrike's lack of focus on reliability, which they deserve, however there's a bigger issue here of trying to avoid or mitigate risky dependencies in the first place that I hope we also get to explore.
Post reply on HN