Live data from Hacker News

CrowdStrike will be liable for damages in France, based on the OVH precedent

thehftguy.com

251–260 of 285 posts

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#251
post #225

Earlier quoted context omitted.

There is, the TPM. SSH keys can easily be stored and used from there.

I can do that as a user? With what utility?

Yep: https://incenp.org/notes/2020/tpm-based-ssh-key.html

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#252

Earlier quoted context omitted.

> If you aren’t talking across continents there is no need to speak two languages Continents have nothing to do with this. If you live in the UK and need to talk to people in the USA and Australia, you can be monolingual and still speak with people in three continents. If you live in Switzerland, you may need to speak 3 languages just to be able to talk with all your neighbors.

There is also an abundance of people who don't speak English, or prefer not to, right here in North America. The Canadian province of Quebec, for instance, legally mandates bilingual signage and generally prefers French. And Mexico is right there too. There are also a great many families in the US whose first-generation members have limited English.

There are also many of us who have family in the US since the 1860's and still speak (Alemannic) German at home and in the surrounding community.

This also goes notwithstanding the indigenous peoples, whose Diné bizaad and Tsalagi, for example, are also spoken here.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#253
post #244

Earlier quoted context omitted.

yes, many non US firms do exactly that for international announcements: - use "second half of ", "begin of", 3 quartal of, etc. - or a specific month if they want to be more precise also for western focused announcements they also use "holliday session" as their tends to be a holliday session in most countries in both summer and winter (through their start differs _a lot_, but it tends to just work out if you release…

The meteorological dates for "summer" correspond to June 1 to August 31. That straddles 2 quarters and both halves of the year. What are you going to do if a product launch is in July (+- 1 month)? You can't really use Q3 or H2 because neither of them fully captures that 3 month period.

Then use two seasons in the announcement. It's not hard. ;)

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#254

Earlier quoted context omitted.

I don't want an OS that lets me run executables from email - I've never actually has to do that. I do want an OS that I can tell to run "Firefox, Anki, Thunderbird", once, and nothing else will run.

Ok, how about an image in an email? Or a PDF receipt? How about clicking a link online? All of these have a serious potential to infect your system with malware.

I really don't want executables in PDF files or email. Really, I don't.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#255

Earlier quoted context omitted.

I read an article that stated that Microsoft lost an anti-trust court case against the EU in which the EU mandated that they allow third party competitors to provide this service. Microsoft has its own solution called Windows Defender. https://www.theregister.com/2024/07/22/windows_crowdstrike_k...

It's more nuanced than that. They have to provide the same APIs to third party security vendors that they use themselves. They can come up with something more shielded as Apple has done, they just have to eat their own dog food and can't make an exception for defender. That's all. Blaming the EU here is pure spin.

yes (it's a spin) also e.g. on Linux Falcon could have conceptual created the same kind of driver as for windows but opted to use eBPF

for a lot of things on Windows there isn't anything like eBPF (yet, it's wip, but likely will still take quite a while until it's usable)

the EU spin would only work if CrowdStrict is fully incompetent like a lot of people want you to believe. I.e. they don't do any testing, don't do any config validation and doesn't know what they are doing at all

but that simply isn't true at all

This doesn't mean that they didn't act negligent, as far as we can tell they relied on some data format validation instead by their server + signing (or something similar) instead of _also_ having robust parsing and that is enough against best practices to be called negligent. And there were other points which bubbled up in the last week which point to other negligent behavior unrelated to the bug. But company ending up with some negligent behavior and them being fully incompetent are very far away, let's be honest most IT companies today have ended up with some negligent behavior they have lite direct/short term/fast feedback motivation to fix (hence it doesn't happen)

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#256
post #244

Earlier quoted context omitted.

yes, many non US firms do exactly that for international announcements: - use "second half of ", "begin of", 3 quartal of, etc. - or a specific month if they want to be more precise also for western focused announcements they also use "holliday session" as their tends to be a holliday session in most countries in both summer and winter (through their start differs _a lot_, but it tends to just work out if you release…

The meteorological dates for "summer" correspond to June 1 to August 31. That straddles 2 quarters and both halves of the year. What are you going to do if a product launch is in July (+- 1 month)? You can't really use Q3 or H2 because neither of them fully captures that 3 month period.

say roughly around July but the we have not yet committed to an exact release month

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#257
post #211
post #202

Earlier quoted context omitted.

They didn't follow testing or deployment best practices either.

IIRC their QA team was impacted by the most recent round of layoffs. Dumping those responsibilities onto devs isn't a great solution to begin with, and especially not when the product is a complete trash fire.

yeah you really shouldn't layoff a QA team if you do something like that that's just pure negligence

(through yo have to make sure you QA team works properly, i.e. in tandem with your dev not in fight with them, to many QA teams are a mess, but QA is important)

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#258
post #244

Earlier quoted context omitted.

The meteorological dates for "summer" correspond to June 1 to August 31. That straddles 2 quarters and both halves of the year. What are you going to do if a product launch is in July (+- 1 month)? You can't really use Q3 or H2 because neither of them fully captures that 3 month period.

say roughly around July but the we have not yet committed to an exact release month

"roughly around July but the we have not yet committed to an exact release month" sounds way more clunky than "this summer".

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#259

Earlier quoted context omitted.

Languages as in knowing two systems. Sort of like how most people don’t need to know international date or thousands/decimal separator conventions, but those functioning internationally—whether due to being well travelled or senior enough to conduct international trade and/or relations—do. My going to a conference in India and arguing over the lakh/crore system isn’t useful to anyone [1]. [1] https://en.m.wikipedia.o…

Even then, continents have little to do with it. The Indian numbering system is indeed used in much of Asia - but it's not used in Russia for example. If you live in Vladivostok, you might need to learn these two systems even if you never do business with anyone farther than 300km from you. And in Europe there are numerous differences between countries of this kind - Germans and a few others use different number sepa…

> (1,000 is 1000 in France or the UK or Spain, but 1 in Germany or Romania)

No, France and Spain follow the same standard as Germany: dots as thousands separators, a comma as the decimal separator. Actually most of Europe does the same, the only exceptions being the UK and Ireland:

https://en.wikipedia.org/wiki/Decimal_separator#/media/File:...

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#260
post #59

Can someone explain to me why the protections that Falcon provides, are not provided by the OS itself? I am not completely naive, I've secured quite a few critical Linux servers, but with Windows it seems that there do not exist the same clear roles of security. Contrast with Red Hat or even Canonical, where is feels like I'm (correctly) fighting the security of the systems to get them into a state where my users can…

Linux can't be secured out of the box to do anything that Falcon does. If you use AuditD, eBPF and things like GRSecurity patches you might get into a good state, but it's still not the same thing at all. it might be secure depending on your linuxfoo, but it's not the same thing as running EDR which will help correlate system behavior across different systems etc. and look with much more depth into process behaviors…

I disagree that windows defender is trash. Its’ initial introduction mitigated a lot of malware problems of the early 2000’s.

Sure, it may not be the best, but most vendor solutions aren’t either. Case study: crowdstrike.

Post reply on HN