Earlier quoted context omitted.
I acquainted with a guy at a conference in US and he was genuinely surprised I had no idea, how long US mile is. I explained him, we use metric system and his response was “but don’t you learn *the standard* system in ache school?” I did not know, how to respond.
AFAIK USA people learn both systems in school. So it understandable if they are not aware that the rest of the world don't know about their system, miles, inches, feet, gallons, pounds, etc, unless they are into American culture (books, movies).
CrowdStrike will be liable for damages in France, based on the OVH precedent
221–230 of 285 posts
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#222Earlier quoted context omitted.
The cat-and-mouse game is between OS security features and hackers. AV software is not a crutch, it's an extra level of defense. All OS kernels are vulnerable to malware - this is a 100% given at this moment in history. The question is how to mitigate this problem, and AV is one component of that, as are firewalls, network-level intrusion prevention systems, and a whole host of other security software. Maybe some day…
I don't want an OS that lets me run executables from email - I've never actually has to do that. I do want an OS that I can tell to run "Firefox, Anki, Thunderbird", once, and nothing else will run.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#223Earlier quoted context omitted.
Somehow related, expressions like "next summer", "starting this spring" and such on public global announcements make absolutely nonsense if you are in the southern hemisphere (like a big percentage of the global population)
What are they supposed to use instead? "Starting in Q3/H2"?
What's wrong with using a calendar date like may the 1st? I know that there are other calendars too. But is more manageable IMO.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#224Earlier quoted context omitted.
Windows does have Defender, which does some amount of tracking signatures and heuristics of various types of malware. It has not, however, proved enough to fend off different real world problems like ransomware. Hence, the market for 3rd party solutions that are more aggressive. And to keep up with real world threats, they have to update often. And have to run at high privilege levels. So now you have the situation w…
I read that a lot, but nobody ever provide supporting evidence. To me, this sounds a bit like 3rd party security marketing being really effective.
A screenshot of one comparison from Mitre:
You can do more of them here: https://attackevals.mitre-engenuity.org/
It's not a huge difference, but there's a difference.
Also, I have no relationships or investments, etc. Not shilling.
Edit: Also, that url slug from imgur. Heh.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#225Earlier quoted context omitted.
Actually, arguably Windows has some impressive security features unseen on any other mainstream OS, they're just not used by default and - realistically - would be hard to enable on general purpose / non-corporate computers. For example, by comparison, Linux is in the stone age here. Do you even need AV if untrusted code can't run in the first place? * Application whitelisting - with just bare old AppLocker, Windows…
>- By comparison, Kerberos tickets on Linux reside as files on disk, SSH user & host keys reside as files on disk and loaded into sshd/gpg-agent memory, x.509 keypairs reside as files on disk & process memory etc etc. Wouldn't it be nice to have them protected somehow? To my knowledge, nothing exists for this on Linux. I have always wondered about that; there has to be a more secure control method for those secrets.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#226Earlier quoted context omitted.
> we use metric system and his response was “but don’t you learn *the standard* system in ache school?” I did not know, how to respond It’s just a difference in travel and seniority. If you aren’t talking across continents there is no need to speak two languages.
> If you aren’t talking across continents there is no need to speak two languages Continents have nothing to do with this. If you live in the UK and need to talk to people in the USA and Australia, you can be monolingual and still speak with people in three continents. If you live in Switzerland, you may need to speak 3 languages just to be able to talk with all your neighbors.
There are also a great many families in the US whose first-generation members have limited English.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#227Earlier quoted context omitted.
> How do you actively detect a malware agent running in user space using stealth Depending how advanced the attacker is, check the executing binary maps back to the actual expected name and location on disk. Make sure the executable and libraries used at runtime are the correct ones matching hashes of known good qualities. Ensure the process tree structure has an expected structure, ie "bash" isnt starting a process…
Who collects and maintains all these lists of known good/expected configurations? Should the kernel know that apache shouldn't be launched from root? How about autocad, is that ok to be launched from bash? What directories should autocad be reading/writing?
Stock Windows actually implements something along these lines, called "protected folders" or similar. It's inactive by default (meaning every program can access every folder). It's quite easy to define a list of "protected" folders. But the implementation is quite stupid: if a program asks for access to one of the folders on the list, you can either refuse, or allow it to access it... as well as everything else on that list!
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#228Earlier quoted context omitted.
Isn’t it 60 days in the whole EU for physical objects bought via internet?
14 days - 1 year of repairs if you didn't break it https://europa.eu/youreurope/citizens/consumers/shopping/gua...
But after 1 year you have to show that it's the vendors fault instead of the vendor having to show it was your fault so often "de-facto" 1 year.
Various exceptions include for stuff like food, underware etc.
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#229Earlier quoted context omitted.
Microsoft has a high share in this area but enterprise security is generally a very competivite market. Microsoft may even move into #1 position as a fallout from this debacle becasue the market share between them and the #1 CS is very small (that does not mean people actually buy more Ms btw... if that needs to be said ;) This is not neccesarily a good thing for MSFT as it will 100% trigger regulator rage in the EU.…
Maybe a better market share graphic without a paywall. A little dated, but close enough. https://www.microsoft.com/en-us/security/blog/wp-content/upl...
Re: CrowdStrike will be liable for damages in France, based on the OVH precedent
#230Earlier quoted context omitted.
Somehow related, expressions like "next summer", "starting this spring" and such on public global announcements make absolutely nonsense if you are in the southern hemisphere (like a big percentage of the global population)
What are they supposed to use instead? "Starting in Q3/H2"?
- use "second half of ", "begin of", 3 quartal of, etc.
- or a specific month if they want to be more precise
also for western focused announcements they also use "holliday session" as their tends to be a holliday session in most countries in both summer and winter (through their start differs _a lot_, but it tends to just work out if you release early enough)