Live data from Hacker News

CrowdStrike to Delta: Stop pointing at us

wsj.com

41–50 of 76 posts

Re: CrowdStrike to Delta: Stop pointing at us

#41
post #21

The Microsoft part of this I find interesting, I mean I guess it would be standard legal practice to also go after them even if it is thrown out. But that one is weird. Maybe Microsoft encouraged Delta to use Crowdstrike, then ok I could see the case. But if it is anything related to how Windows works, that seems like a stretch. Yes Windows could be better, but I don't like the idea that the OS provider could be sued…

> While I am sure that Delta's IT department was understaffed, this was also a unique situation. If you spent the time to make a well optimized machine for rolling out updates, things were automated, and you expected things to go wrong but I would have never anticipated every Windows machine being unable to boot. That is an extra-ordinary situation. I doubt any IT department is really staffed to be able to handle that situation happening. You don't expect to need to deal with every machine you have, its honestly kinda unrealistic.

I do not believe this will be the last of its nature in our generation. It should very much be already have been accounted for. The basics and fundamentals of information security apply despite what interpretations of insurance policies or certifications say. Let this be a lesson to not introduce single points of failure into critical systems without having prepared for their unavailaility or misbehaviour (yes, that includes your ISPs, cloud, and SaaS providers

Re: CrowdStrike to Delta: Stop pointing at us

#42
post #34

One issue that hasn't received enough attention comes from a comment on Dave Plummer's video on the CrowdStrike outage. Dave Plummer is a former Windows engineer and runs a YouTube channel call Dave's Garage. @zug-zug wrote: > While this is technically what crashed machines it isn't the worst part. > CS Falcon has a way to control the staging of updates across your environment. businesses who don't want to go out of…

Relevant to dave plummer: https://news.ycombinator.com/item?id=39813625 > Now, as to the tidbit. Dave Plummer ran a scam company that was sued by Washington State in 2006, "SoftwareOnline.com, Inc. ". He actually left Microsoft specifically to run this company. > Court documents can be seen here: https://www.atg.wa.gov/news/news-releases/attorney-general-s ... You can find David W. Plummer listed in the court complai…

[deleted]

Re: CrowdStrike to Delta: Stop pointing at us

#43
post #34

One issue that hasn't received enough attention comes from a comment on Dave Plummer's video on the CrowdStrike outage. Dave Plummer is a former Windows engineer and runs a YouTube channel call Dave's Garage. @zug-zug wrote: > While this is technically what crashed machines it isn't the worst part. > CS Falcon has a way to control the staging of updates across your environment. businesses who don't want to go out of…

Relevant to dave plummer: https://news.ycombinator.com/item?id=39813625 > Now, as to the tidbit. Dave Plummer ran a scam company that was sued by Washington State in 2006, "SoftwareOnline.com, Inc. ". He actually left Microsoft specifically to run this company. > Court documents can be seen here: https://www.atg.wa.gov/news/news-releases/attorney-general-s ... You can find David W. Plummer listed in the court complai…

That was like 18 years ago and not relevant to the topic or thread. People make mistakes in life and deserve to be able to move past them.

Re: CrowdStrike to Delta: Stop pointing at us

#44

One issue that hasn't received enough attention comes from a comment on Dave Plummer's video on the CrowdStrike outage. Dave Plummer is a former Windows engineer and runs a YouTube channel call Dave's Garage. @zug-zug wrote: > While this is technically what crashed machines it isn't the worst part. > CS Falcon has a way to control the staging of updates across your environment. businesses who don't want to go out of…

If this is true, this is the smoking gun that screams "negligence" from a legal standpoint and CrowdStrike's insurers will be making a lot of payouts.

Re: CrowdStrike to Delta: Stop pointing at us

#45
post #31

I sense legal escalation coming.

Tbf, this is like a goldmine for the lawyers right now, on both sides! It's not clear, it's ambiguous, needs to be litigate and decided and contracts are challenged, and damages occurred all round, etc. Hundreds of millions in fees are gonna get floated, and years of litigation.

Re: CrowdStrike to Delta: Stop pointing at us

#46
It's absolutely nuts to me that any entity has the Full Software Authority (FSA), which is the ability to push out (closed-source) kernel-mode software to a mind-boggling large fraction of the world's computing base.

Talk about a strategic vulnerability. "It's for security" they said.

Now imagine that a nefarious actor managed to compromise the FSA and push a stealth root kit. I shudder to think about how a full-out cyberwar would go.

Re: CrowdStrike to Delta: Stop pointing at us

#47

Looks like the common race to the bottom is happening: which is the lawyers have taken control.

The lawyers have always been in control since the beginning. And more so today. It's part of the idea of the United States of America.

More specifically, a huge amount of legal negotiation goes into a B2B SaaS deal between parties of this size up front, incl liability caps, SLAs, and MSA, etc. One of the bigger obstacles in the sales cycle even (getting legal alignment).

Re: CrowdStrike to Delta: Stop pointing at us

#49
post #21

The Microsoft part of this I find interesting, I mean I guess it would be standard legal practice to also go after them even if it is thrown out. But that one is weird. Maybe Microsoft encouraged Delta to use Crowdstrike, then ok I could see the case. But if it is anything related to how Windows works, that seems like a stretch. Yes Windows could be better, but I don't like the idea that the OS provider could be sued…

delta is responsible for delta, there are no absolutes in software and systems, at the end of the day delta has to be ready for anything, if they choose to under staff and rely on black box software..that is a choice they make. Microsoft was forced by EU, and crowdstrike had a (rather large) mistake, companies have them you know. It's the same reason why i still backup my google photos and drive.

Re: CrowdStrike to Delta: Stop pointing at us

#50
post #34

One issue that hasn't received enough attention comes from a comment on Dave Plummer's video on the CrowdStrike outage. Dave Plummer is a former Windows engineer and runs a YouTube channel call Dave's Garage. @zug-zug wrote: > While this is technically what crashed machines it isn't the worst part. > CS Falcon has a way to control the staging of updates across your environment. businesses who don't want to go out of…

Relevant to dave plummer: https://news.ycombinator.com/item?id=39813625 > Now, as to the tidbit. Dave Plummer ran a scam company that was sued by Washington State in 2006, "SoftwareOnline.com, Inc. ". He actually left Microsoft specifically to run this company. > Court documents can be seen here: https://www.atg.wa.gov/news/news-releases/attorney-general-s ... You can find David W. Plummer listed in the court complai…

[deleted]
Post reply on HN