Live data from Hacker News

CrowdStrike ex-employees: 'Quality control was not part of our process'

semafor.com

111–120 of 311 posts

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#111
post #42

Earlier quoted context omitted.

Also it's the _second_ time that they had done this in a few short months. They had previous bricked linux hosts earlier with a similar type of update. So we also know that they don't learn from their mistakes.

The blame for the Linux situation isn’t as clear cut as you make it out to be. Red hat rolled out a breaking change to BPF which was likely a regression. That wasn’t caused directly by a crowdstrike update.

It's not about the blame, it's about how you respond to incidents and what mitigation steps you take. Even if they aren't directly responsible, they clearly didn't take proper mitigation steps when they encountered the problem.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#112
post #51

What are some alternatives to CrowdStrike?

Personal: Nothing - Windows Defender is built into Windows. Business: Nothing - Windows Defender Advanced Threat Protection is built into the higher Microsoft 365 license tiers. It amazes me people chose to pay money to have all their PCs bluescreen.

if you had used 'some' before 'people' i could agree but some industries have to use a siem or they can be fined, so, i mean if there's a list of siems that are definitely not going to ever crash by messing around in the kernel lets get a list going

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#113
post #102
post #80

Earlier quoted context omitted.

Conspiracy theory time. Because Apple is the only OS company that has reliably proven that it won't decrypt hard drives at government request.

It depends on the country it is in, it rejects the US government's request. But it fully complies with any request from the Chinese government

I'd be interested to learn more about that.

My mental model was that Apple provides backdoor decryption keys to China in advance for devices sold in China/Chinese iCloud accounts, but that they cannot/will not bypass device encryption for China for devices sold outside of the country/foreign iCloud accounts.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#115
post #84

Earlier quoted context omitted.

Ideally secrets never leave secure enclaves and humans at the organization can't even access them. It's totally insane to send them to a remote service controlled by another organization.

Essentially, it’s straddling two extremes: 1) employees are trusted with secrets, so we have to audit that employees are treating those secrets securely (via tracking, monitoring, etc) 2) we don’t allow employees to have access to secrets whatsoever, therefore we don’t need any auditing or monitoring

You give employees the ability to use the secrets, and that usage is tracked and audited.

It works the same way for biometrics like face unlock on mobile phones

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#116
Not justifying what they did with qc, but qc is missing from quite a few places in software development that I've been apart of. People might get the impression from the article that every software project is well tested, whereas in my experience most are rushed out.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#117

Earlier quoted context omitted.

Why would you trust a company no-man any more than a company yes-man? They both have agendas and biases. Is it just that you personally prefer one set of biases (anti-company) more than the other (pro-company)?

Yes, I am very much biased toward being anti-company and I make no apologies for that. I've been in the corporate world long enough to know first-hand the sins that PR and corporate management commits on the company's behalf and the harm it does. I find information coming from the individual more reliable than having it filtered through corpo PR, legal, ass-covering nonsense, the latter group often wanting to preserv…

OK just checking. Nice that you at least acknowledge your bias.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#118
post #84

Earlier quoted context omitted.

Ideally secrets never leave secure enclaves and humans at the organization can't even access them. It's totally insane to send them to a remote service controlled by another organization.

Essentially, it’s straddling two extremes: 1) employees are trusted with secrets, so we have to audit that employees are treating those secrets securely (via tracking, monitoring, etc) 2) we don’t allow employees to have access to secrets whatsoever, therefore we don’t need any auditing or monitoring

Exporting to a SIEM does not correlate to either of those extremes. It’s stupidity and makes auditing worse

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#120
post #12

Earlier quoted context omitted.

Why would a UX designer be involved in any way, shape, or form in kernel level code patches? They would literally never ship an update if they had that many hands in the pot for something completely unrelated. Should they also have their sales reps and marketing folks pre-brief before they make any code changes?

A UX designer might have told them it was a bad idea to deploy the patch widely without testing a smaller cohort, for instance. That’s an obvious measure that they skipped this time.

But that doesn't have anything to do with what UX designers typically do
Post reply on HN