Live data from Hacker News

CrowdStrike ex-employees: 'Quality control was not part of our process'

semafor.com

101–110 of 311 posts

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#101
post #51

What are some alternatives to CrowdStrike?

Personal: Nothing - Windows Defender is built into Windows. Business: Nothing - Windows Defender Advanced Threat Protection is built into the higher Microsoft 365 license tiers. It amazes me people chose to pay money to have all their PCs bluescreen.

mdatp is also a virus. So slow…

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#102
post #80
post #44

Earlier quoted context omitted.

But why only forced on MacOS? I think some configurability would be great. I would like to provide an allow list or the ability to redact. Or exclude specific host groups. We all have different levels of acceptable risk

Conspiracy theory time. Because Apple is the only OS company that has reliably proven that it won't decrypt hard drives at government request.

It depends on the country it is in, it rejects the US government's request. But it fully complies with any request from the Chinese government

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#103
post #99

Earlier quoted context omitted.

Keeping secrets and other sensitive data out of your SIEM is a very important part of SIEM design. Depending on what you’re dealing with you might want to tokenize it, or redact it, but you absolutely don’t want to don’t want to just ingest them in plaintext. If you’re a PCI company then ending up with a credit card number in your SIEM can be a massive disaster. Because you’re never allowed to store that in plaintext…

> But I have no idea what they’d do if your SIEM somehow became full of credit card numbers, that probably is unfixable… You'd get rid of it.

If that’s straightforward then congratulations, you’ve failed your assessment for not having immutable log retention.

They certainly wouldn’t let you keep it there, but if your SIEM was absolutely full of cardholder data, I imagine they’d require you to extract ALL of it, redact the cardholder data, and the import it to a new instance, nuking the old one. But for a QSA to sign off on that they’d be expecting to see a lot of evidence that removing the cardholder data was the only thing you changed.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#104
post #12

Earlier quoted context omitted.

If design isn’t involved in QC you’re not doing QC very well. If design isn’t plugged into development process enough to understand QC then you’re not doing design very well.

Why would a UX designer be involved in any way, shape, or form in kernel level code patches? They would literally never ship an update if they had that many hands in the pot for something completely unrelated. Should they also have their sales reps and marketing folks pre-brief before they make any code changes?

A UX designer might have told them it was a bad idea to deploy the patch widely without testing a smaller cohort, for instance. That’s an obvious measure that they skipped this time.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#105

Earlier quoted context omitted.

I just don't think a company like Crowdstrike has a leg to stand on when leveling the "disgruntled" label in the face of their, let's face it, astoundingly epic fuck up. It's the disgruntled employees that I think would have the most clear picture of what was going on, regardless of them being in QA/QC or not because they, at that point, don't really care any more and will be more forthright with their thoughts. I'd…

Why would you trust a company no-man any more than a company yes-man? They both have agendas and biases. Is it just that you personally prefer one set of biases (anti-company) more than the other (pro-company)?

Yes, I am very much biased toward being anti-company and I make no apologies for that. I've been in the corporate world long enough to know first-hand the sins that PR and corporate management commits on the company's behalf and the harm it does. I find information coming from the individual more reliable than having it filtered through corpo PR, legal, ass-covering nonsense, the latter group often wanting to preserve the status quo than getting out actual info.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#107
post #43
post #36

Found out that the CrowdStrike Mac agent (Falcon) sends all your secrets from environment variables to their cloud hosted SIEM. In plain text. Anyone with access to your CS SIEM can search for GitHub, aws, etc creds. Anything your devs, ops and sec teams use on their Macs. Only the Mac version does this. There is no way to disable this behaviour or a way to redact things. Another really odd design decision. They prob…

Is this really a criticism? Because this has been the case forever with all security and SIEM tools. It’s one of the reasons why the SIEM is the most locked down pieces of software in the business. Realistically, secrets alone shouldn’t allow an attacker access - they should need access to infrastructure or a certificates in machines as well. But unfortunately that’s not the case for many SaaS vendors.

Arbitrary bad practices as status quo without criticism, far from absolving more of the same, demand scrutiny.

Arbitrarily high levels of market penetration by sloppy vendors in high-stakes activities, far from being an argument for functioning markets, demand regulation.

Arbitrarily high profile failures of the previous two, far from indicating a tolerable norm, demand criminal prosecution.

It is recently that this seemingly ubiquitous vendor, with zero-day access to a critical kernel space that any red team adversary would kill for, said “lgtm shipit” instead of running a test suite with consequences and costs (depending on who you listen to) ranging from billions in lost treasure to loss of innocent life.

We know who fucked up, have an idea of how much corrupt-ass market failure crony capitalism could admit such a thing.

The only thing we don’t know is how much worse it would have to be before anyone involved suffers any consequences.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#108
post #80

Earlier quoted context omitted.

Conspiracy theory time. Because Apple is the only OS company that has reliably proven that it won't decrypt hard drives at government request.

This is a true conspiracy .

Seriously? Crowdstrike is obviously NSA just like Kaspersky is obviously KGB and Wiz is obviously Mossad. Why else are counties so anxious about local businesses not using agents made by foreign actors?

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#110
post #83

Critical software infrastructure should be regulated the way critical physical infrastructure is. We don't trust the people who make buildings and bridges to "do the right thing" - we mandate it with regulations and inspections. (When your software not working strands millions of people around the globe, it's critical) And this was just a regular old "accident"; imagine the future, when a war has threat actors trying…

Did you notice that the piece of software in question was apparently installed mostly in companies where regulations and inspections already override sysadmins' common sense? Are you sure the answer is simply more of the same?

I sure noticed how much snark you packed into two sentences!
Post reply on HN