Live data from Hacker News

CrowdStrike will be liable for damages in France, based on the OVH precedent

thehftguy.com

221–230 of 285 posts

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#221
post #198
post #117

Earlier quoted context omitted.

I acquainted with a guy at a conference in US and he was genuinely surprised I had no idea, how long US mile is. I explained him, we use metric system and his response was “but don’t you learn *the standard* system in ache school?” I did not know, how to respond.

AFAIK USA people learn both systems in school. So it understandable if they are not aware that the rest of the world don't know about their system, miles, inches, feet, gallons, pounds, etc, unless they are into American culture (books, movies).

One of the things that USians are taught in school when they learn these two systems is that everyone else uses metric. We're typically taught it in our science classes, because even in the US, scientists still use predominantly (exclusively?) metric. It follows that there's no parallel reason for most foreigners to learn US imperial units, especially in an institutional setting like public school.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#222

Earlier quoted context omitted.

The cat-and-mouse game is between OS security features and hackers. AV software is not a crutch, it's an extra level of defense. All OS kernels are vulnerable to malware - this is a 100% given at this moment in history. The question is how to mitigate this problem, and AV is one component of that, as are firewalls, network-level intrusion prevention systems, and a whole host of other security software. Maybe some day…

I don't want an OS that lets me run executables from email - I've never actually has to do that. I do want an OS that I can tell to run "Firefox, Anki, Thunderbird", once, and nothing else will run.

Ok, how about an image in an email? Or a PDF receipt? How about clicking a link online? All of these have a serious potential to infect your system with malware.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#223
post #219

Earlier quoted context omitted.

Somehow related, expressions like "next summer", "starting this spring" and such on public global announcements make absolutely nonsense if you are in the southern hemisphere (like a big percentage of the global population)

What are they supposed to use instead? "Starting in Q3/H2"?

Maybe you are not aware but while it is summer in the northern hemisphere in the southern hemisphere you have winter (and so on). So, speaking of seasons means exactly the opposite depending on which hemisphere you are.

What's wrong with using a calendar date like may the 1st? I know that there are other calendars too. But is more manageable IMO.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#224
post #40

Earlier quoted context omitted.

Windows does have Defender, which does some amount of tracking signatures and heuristics of various types of malware. It has not, however, proved enough to fend off different real world problems like ransomware. Hence, the market for 3rd party solutions that are more aggressive. And to keep up with real world threats, they have to update often. And have to run at high privilege levels. So now you have the situation w…

I read that a lot, but nobody ever provide supporting evidence. To me, this sounds a bit like 3rd party security marketing being really effective.

There are actual differences, and eval frameworks to get the details you're asking for.

A screenshot of one comparison from Mitre:

https://imgur.com/a/WH0reRy

You can do more of them here: https://attackevals.mitre-engenuity.org/

It's not a huge difference, but there's a difference.

Also, I have no relationships or investments, etc. Not shilling.

Edit: Also, that url slug from imgur. Heh.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#225

Earlier quoted context omitted.

Actually, arguably Windows has some impressive security features unseen on any other mainstream OS, they're just not used by default and - realistically - would be hard to enable on general purpose / non-corporate computers. For example, by comparison, Linux is in the stone age here. Do you even need AV if untrusted code can't run in the first place? * Application whitelisting - with just bare old AppLocker, Windows…

>- By comparison, Kerberos tickets on Linux reside as files on disk, SSH user & host keys reside as files on disk and loaded into sshd/gpg-agent memory, x.509 keypairs reside as files on disk & process memory etc etc. Wouldn't it be nice to have them protected somehow? To my knowledge, nothing exists for this on Linux. I have always wondered about that; there has to be a more secure control method for those secrets.

There is, the TPM. SSH keys can easily be stored and used from there.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#226

Earlier quoted context omitted.

> we use metric system and his response was “but don’t you learn *the standard* system in ache school?” I did not know, how to respond It’s just a difference in travel and seniority. If you aren’t talking across continents there is no need to speak two languages.

> If you aren’t talking across continents there is no need to speak two languages Continents have nothing to do with this. If you live in the UK and need to talk to people in the USA and Australia, you can be monolingual and still speak with people in three continents. If you live in Switzerland, you may need to speak 3 languages just to be able to talk with all your neighbors.

There is also an abundance of people who don't speak English, or prefer not to, right here in North America. The Canadian province of Quebec, for instance, legally mandates bilingual signage and generally prefers French. And Mexico is right there too.

There are also a great many families in the US whose first-generation members have limited English.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#227

Earlier quoted context omitted.

> How do you actively detect a malware agent running in user space using stealth Depending how advanced the attacker is, check the executing binary maps back to the actual expected name and location on disk. Make sure the executable and libraries used at runtime are the correct ones matching hashes of known good qualities. Ensure the process tree structure has an expected structure, ie "bash" isnt starting a process…

Who collects and maintains all these lists of known good/expected configurations? Should the kernel know that apache shouldn't be launched from root? How about autocad, is that ok to be launched from bash? What directories should autocad be reading/writing?

Seeing how on users' machines the most interesting data to read is in the user's home folder, I'd argue it's actually pretty easy to partition these. Autocad should read and write in ~/autocad. Maybe in ~/Downloads? But definitely not in ~/.ssh or ~/.aws.

Stock Windows actually implements something along these lines, called "protected folders" or similar. It's inactive by default (meaning every program can access every folder). It's quite easy to define a list of "protected" folders. But the implementation is quite stupid: if a program asks for access to one of the folders on the list, you can either refuse, or allow it to access it... as well as everything else on that list!

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#228

Earlier quoted context omitted.

Isn’t it 60 days in the whole EU for physical objects bought via internet?

14 days - 1 year of repairs if you didn't break it https://europa.eu/youreurope/citizens/consumers/shopping/gua...

2 years in most places --

But after 1 year you have to show that it's the vendors fault instead of the vendor having to show it was your fault so often "de-facto" 1 year.

Various exceptions include for stuff like food, underware etc.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#229
post #177
post #122

Earlier quoted context omitted.

Microsoft has a high share in this area but enterprise security is generally a very competivite market. Microsoft may even move into #1 position as a fallout from this debacle becasue the market share between them and the #1 CS is very small (that does not mean people actually buy more Ms btw... if that needs to be said ;) This is not neccesarily a good thing for MSFT as it will 100% trigger regulator rage in the EU.…

Maybe a better market share graphic without a paywall. A little dated, but close enough. https://www.microsoft.com/en-us/security/blog/wp-content/upl...

CrowdStrike moved ahead in 2023 for some reason to be #1

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#230
post #219

Earlier quoted context omitted.

Somehow related, expressions like "next summer", "starting this spring" and such on public global announcements make absolutely nonsense if you are in the southern hemisphere (like a big percentage of the global population)

What are they supposed to use instead? "Starting in Q3/H2"?

yes, many non US firms do exactly that for international announcements:

- use "second half of ", "begin of", 3 quartal of, etc.

- or a specific month if they want to be more precise

also for western focused announcements they also use "holliday session" as their tends to be a holliday session in most countries in both summer and winter (through their start differs _a lot_, but it tends to just work out if you release early enough)

Post reply on HN