Live data from Hacker News

CrowdStrike to Delta: Stop pointing at us

wsj.com

31–40 of 76 posts

Re: CrowdStrike to Delta: Stop pointing at us

#32
Delta, and others, clearly failed to account for the full risk of installing CrowdStrike across their fleet. If they did account for it, they gave it little enough weight to not have a path to recovery ready to go in a disaster recovery scenario.

This is certainly a learning experience for MSFT and CS, but I think it's foolish to say they are at fault. Delta has a choice in what software they employ.

Re: CrowdStrike to Delta: Stop pointing at us

#33
post #14

Earlier quoted context omitted.

Am I right in thinking Delta could have chosen when the update was distributed to its infrastructure? In my mind, a quick test run of the update on a VM before letting it roll out globally would have revealed the BSOD boot loop.

AFAIK crowdstrike can push updates at any time at any host. There are staging areas they may use, but don't have to (particularly for definitions updates). Crowdstrike should have done a better job , but Delta chose them (to offload the responsibility and work) and now they're claiming foul. They knew the risk. This is a classic executive play of claiming the fault lies in the consultants/vendor and taking no respons…

Just shows how many planes would be falling out of the sky if there weren't federally mandated safety systems, secondary hydraulic circuits, and failover hot spares at nearly every layer of the stack. Delta should've had backup systems, just like their planes do.

Re: CrowdStrike to Delta: Stop pointing at us

#34

One issue that hasn't received enough attention comes from a comment on Dave Plummer's video on the CrowdStrike outage. Dave Plummer is a former Windows engineer and runs a YouTube channel call Dave's Garage. @zug-zug wrote: > While this is technically what crashed machines it isn't the worst part. > CS Falcon has a way to control the staging of updates across your environment. businesses who don't want to go out of…

Relevant to dave plummer: https://news.ycombinator.com/item?id=39813625

> Now, as to the tidbit. Dave Plummer ran a scam company that was sued by Washington State in 2006, "SoftwareOnline.com, Inc. ". He actually left Microsoft specifically to run this company.

> Court documents can be seen here: https://www.atg.wa.gov/news/news-releases/attorney-general-s... You can find David W. Plummer listed in the court complaint.

> The short of it is that it was an online software scam company that tricked people into downloading fake Anti-virus and security software using online ads, and then the software delivered additional adware and nagware onto users machines.

Re: CrowdStrike to Delta: Stop pointing at us

#36
post #26
post #22

Earlier quoted context omitted.

...because all CrowdStrike had to do was say "oops, we f*%&/$d up the last update, here's a fixed one", while Delta's IT had to locate all BSODing devices and somehow recover them?

This is just their response to a legal challenge. If we're asking rhetorical questions, then "why wouldn't CrowdStrike's lawyers try to defer responsibility and not pay millions of dollars?". Otherwise it's reading a bit too much into it and the courts will sort it out. > CrowdStrike said Sunday that its liability is contractually capped at an amount in the “single-digit millions.” That's probably a key question too^

Isn't there a legal/lawyer equivalent to saying the wrong thing to cops. E.g. If you as a person lie or mislead during questioning and that adds weight to your being guilty during trial.

So lawyers trying to pawn this off and use stupid legalese to shift blame, make or ask time-wasting accusations etc. I'm not a lawyer or versed in all the legal stuff, but something smells like a double standard here.

Re: CrowdStrike to Delta: Stop pointing at us

#37
I think CRWD is trying hard to close the litigation door here. If the litigation goes to court and even if they managed to reach agreement for a fairly small amount, say 50M, it's going to open doors for much more later.

I think their lawyers are trying hard to convince Delta to not sue them and they will pay in back channels. As long as it's obstructes from public news, it's a win for them.

Re: CrowdStrike to Delta: Stop pointing at us

#38

It sounds a lot like CrowdStrike is saying "Delta should have known better than to rely on our software for critical functions." Which may be a fair statement, but I think it's also fair to litigate whether or not this post-incident statement is consistent with how CrowdStrike sold their software to Delta.

Did CS claim that their software is infallible? Sales isn't shy to take liberties but this would surprise me.

Re: CrowdStrike to Delta: Stop pointing at us

#39
I can see CS's argument here. Most other airlines were back up within the day of the update going out but Delta slogged on and it's outage continued for several days. If Delta and all other airlines experienced a multi-day outage then yeah I see what Delta is saying, but the fact that all other carriers were up and running within the day while Delta took upwards of a week has me thinking this is more on Delta's internal IT policies/controls/etc rather than CS.

Re: CrowdStrike to Delta: Stop pointing at us

#40
post #34

One issue that hasn't received enough attention comes from a comment on Dave Plummer's video on the CrowdStrike outage. Dave Plummer is a former Windows engineer and runs a YouTube channel call Dave's Garage. @zug-zug wrote: > While this is technically what crashed machines it isn't the worst part. > CS Falcon has a way to control the staging of updates across your environment. businesses who don't want to go out of…

Relevant to dave plummer: https://news.ycombinator.com/item?id=39813625 > Now, as to the tidbit. Dave Plummer ran a scam company that was sued by Washington State in 2006, "SoftwareOnline.com, Inc. ". He actually left Microsoft specifically to run this company. > Court documents can be seen here: https://www.atg.wa.gov/news/news-releases/attorney-general-s ... You can find David W. Plummer listed in the court complai…

The term “ad hominem” gets casually thrown around quite a bit in these parts, but boy howdy this is the literal textbook case of it. Plummer’s not one of the good guys, noted. Is he factually wrong?
Post reply on HN