Live data from Hacker News

CrowdStrike to Delta: Stop pointing at us

wsj.com

21–30 of 76 posts

Re: CrowdStrike to Delta: Stop pointing at us

#21
The Microsoft part of this I find interesting, I mean I guess it would be standard legal practice to also go after them even if it is thrown out. But that one is weird.

Maybe Microsoft encouraged Delta to use Crowdstrike, then ok I could see the case.

But if it is anything related to how Windows works, that seems like a stretch. Yes Windows could be better, but I don't like the idea that the OS provider could be sued for a piece of software causing problems. That seems... dangerous.

Regarding Delta. This seems like an interesting situation. Apparently Crowdstrike offered people to help, but how many people and where. Realistically how much help would they have been able to help given that it isn't like this was isolated to Delta and I imagine their people were stretched pretty thin. And importantly what exactly was the help provided. I don't see any information about this.

While I am sure that Delta's IT department was understaffed, this was also a unique situation. If you spent the time to make a well optimized machine for rolling out updates, things were automated, and you expected things to go wrong but I would have never anticipated every Windows machine being unable to boot. That is an extra-ordinary situation. I doubt any IT department is really staffed to be able to handle that situation happening. You don't expect to need to deal with every machine you have, its honestly kinda unrealistic.

It will be interesting to watch this one play out in the courts. Because at the end of the day the vast majority of the blame for this entire situation is on Crowdstrike. The companies were handed a situation that we were not prepared for.

Re: CrowdStrike to Delta: Stop pointing at us

#22
post #19
post #16

> a “misleading narrative” that the cybersecurity company was responsible for the airline’s tech decisions and response to the outage Am I reading this right that this amounts to "you decided yourself to install our software on your devices, you should have known better?"

They seem to be teasing a narrative that has yet to be released: > “Should Delta pursue this path, Delta will have to explain to the public, its shareholders, and ultimately a jury why CrowdStrike took responsibility for its actions—swiftly, transparently, and constructively—while Delta did not,” wrote Michael Carlinsky, an attorney at law firm Quinn Emanuel Urquhart & Sullivan. or maybe it's just how Delta didn't ta…

...because all CrowdStrike had to do was say "oops, we f*%&/$d up the last update, here's a fixed one", while Delta's IT had to locate all BSODing devices and somehow recover them?

Re: CrowdStrike to Delta: Stop pointing at us

#23
It sounds a lot like CrowdStrike is saying "Delta should have known better than to rely on our software for critical functions."

Which may be a fair statement, but I think it's also fair to litigate whether or not this post-incident statement is consistent with how CrowdStrike sold their software to Delta.

Re: CrowdStrike to Delta: Stop pointing at us

#24

I struggle to understand MSFTs liability here. Can anyone explain to me how Microsoft would be liable for Delta’s outage?

Maybe as an operating system that Delta purchased, its kernel should not crash when a 3rd party software receives a faulty update?

They can’t do anything about a 3rd party software that runs in kernel space

Re: CrowdStrike to Delta: Stop pointing at us

#25

I struggle to understand MSFTs liability here. Can anyone explain to me how Microsoft would be liable for Delta’s outage?

Maybe as an operating system that Delta purchased, its kernel should not crash when a 3rd party software receives a faulty update?

I really dislike this line of thinking because it assumes that Microsoft is responsible for anything you run on your Windows machine.

I should be able to do whatever I want with a computer I buy, but that doesn't mean Microsoft should hold any liability for it. What am I missing here?

Re: CrowdStrike to Delta: Stop pointing at us

#26
post #22
post #19

Earlier quoted context omitted.

They seem to be teasing a narrative that has yet to be released: > “Should Delta pursue this path, Delta will have to explain to the public, its shareholders, and ultimately a jury why CrowdStrike took responsibility for its actions—swiftly, transparently, and constructively—while Delta did not,” wrote Michael Carlinsky, an attorney at law firm Quinn Emanuel Urquhart & Sullivan. or maybe it's just how Delta didn't ta…

...because all CrowdStrike had to do was say "oops, we f*%&/$d up the last update, here's a fixed one", while Delta's IT had to locate all BSODing devices and somehow recover them?

This is just their response to a legal challenge. If we're asking rhetorical questions, then "why wouldn't CrowdStrike's lawyers try to defer responsibility and not pay millions of dollars?". Otherwise it's reading a bit too much into it and the courts will sort it out.

> CrowdStrike said Sunday that its liability is contractually capped at an amount in the “single-digit millions.”

That's probably a key question too^

Re: CrowdStrike to Delta: Stop pointing at us

#27
post #8

I struggle to understand MSFTs liability here. Can anyone explain to me how Microsoft would be liable for Delta’s outage?

Not providing a way to inspect those data except from within kernel drivers (or whatever Windows calls them.) The huge HN thread about what happened weeks ago had some comments about Linux using eBPF to get the same kind of information Crowdstrike needs and Macs having another technology to do the same thing. In both cases the kernel won't crash and take down the machine. Of course it's possible to hog a machine from…

And in turn, Microsoft blames the EU for forcing them to allow an external vendor having kernel level access https://www.euronews.com/next/2024/07/22/microsoft-says-eu-t.... Lot of finger-pointing going around here.

Re: CrowdStrike to Delta: Stop pointing at us

#30
post #6

> CrowdStrike said Sunday that its liability is contractually capped at an amount in the “single-digit millions.” Companies handling critical infrastructure should face more scrutiny imo.

Crowdstrike is not handling critical infrastructure. Delta is. The reality is the industry wants its cake and eat it too. No one forced Delta to buy a software which could force upgrades in their production fleet. They're a billion dollars company, and should put their big boys pants on.

> No one forced Delta to buy a software which could force upgrades in their production fleet.

Except this update was one from CrowdStrike that would ignore Delta's stated update policy.

And they literally said "Oh, yeah, we can configure some updates to bypass your policy". I wonder how well this was communicated to those customers.

Post reply on HN