Live data from Hacker News

CrowdStrike ex-employees: 'Quality control was not part of our process'

semafor.com

181–190 of 311 posts

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#181
post #36

Found out that the CrowdStrike Mac agent (Falcon) sends all your secrets from environment variables to their cloud hosted SIEM. In plain text. Anyone with access to your CS SIEM can search for GitHub, aws, etc creds. Anything your devs, ops and sec teams use on their Macs. Only the Mac version does this. There is no way to disable this behaviour or a way to redact things. Another really odd design decision. They prob…

SIEM = Security information and event management

https://en.wikipedia.org/wiki/Security_information_and_event...

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#182
post #83

Earlier quoted context omitted.

Did you notice that the piece of software in question was apparently installed mostly in companies where regulations and inspections already override sysadmins' common sense? Are you sure the answer is simply more of the same?

I've worked in these enterprise organizations for a long time. They don't run on common sense, or even what one might consider "business sense". Their existing incentives create bizarre behavior. For example, you might think "if a big security exploit happens, the stock price might tank" . So if they value the stock price, they'll focus on security, right?. In reality what they do is focus on burying the evidence of…

While good, those ideas will all increase costs.

Would you pay 10x (or more, even) for these systems? That means 10x the price of water, utilities, transport etc, which then accumulate up the chain to make other things which don't have criticality but do depend on the ones that do.

The thing is, what exists today exists because it's the path of least resistence.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#183
post #62
post #51

What are some alternatives to CrowdStrike?

> What are some alternatives to CrowdStrike? In house competence

But then you can't blame anyone else when shit hits the fan! Isn't that what you're really paying for with EDR? No one is safe from a targeted attack, regardless of software.

/s

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#184
post #36

Found out that the CrowdStrike Mac agent (Falcon) sends all your secrets from environment variables to their cloud hosted SIEM. In plain text. Anyone with access to your CS SIEM can search for GitHub, aws, etc creds. Anything your devs, ops and sec teams use on their Macs. Only the Mac version does this. There is no way to disable this behaviour or a way to redact things. Another really odd design decision. They prob…

Did somebody say GDPR?

Not applicable. It is not related to personal data

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#185
post #182

Earlier quoted context omitted.

I've worked in these enterprise organizations for a long time. They don't run on common sense, or even what one might consider "business sense". Their existing incentives create bizarre behavior. For example, you might think "if a big security exploit happens, the stock price might tank" . So if they value the stock price, they'll focus on security, right?. In reality what they do is focus on burying the evidence of…

While good, those ideas will all increase costs. Would you pay 10x (or more, even) for these systems? That means 10x the price of water, utilities, transport etc, which then accumulate up the chain to make other things which don't have criticality but do depend on the ones that do. The thing is, what exists today exists because it's the path of least resistence.

No, it exists because of all must bow to the deity of increasing shareholder value. Remember that good product is not necessarily equal or even a subset of the easy to sell product. Only once the incentives are aligned towards building quality software that lasts will we see change.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#186
post #71
post #57

Earlier quoted context omitted.

> Because this has been the case forever with all security and SIEM tools. Why? There is no need to send your environment variables.

Otherwise malware can hide in environment variables

Malware can hide in the frame buffer at modern resolutions. They could keep a full copy of it and each frame transition too.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#187
post #36

Found out that the CrowdStrike Mac agent (Falcon) sends all your secrets from environment variables to their cloud hosted SIEM. In plain text. Anyone with access to your CS SIEM can search for GitHub, aws, etc creds. Anything your devs, ops and sec teams use on their Macs. Only the Mac version does this. There is no way to disable this behaviour or a way to redact things. Another really odd design decision. They prob…

It is a common in the world of SIEM. Logs with secrets and PII data is often sent and stays in the SIEM for years until an incident occurs.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#188
post #38

Earlier quoted context omitted.

At some companies, like Boeing, the shorter list would be the gruntled employees.

> gruntled have never heard that word used is a non-negative way

Off-Topic, but do I have a story for you

https://www.ling.upenn.edu/~beatrice/humor/how-i-met-my-wife...

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#189
post #124

Earlier quoted context omitted.

I'd like to clarify: that my job was also to educate, modernize, and improve developer velocity through tooling and framework updates / changes (impacting every team in my department (UX / frontend engineering)). Reviewing tests is part of PR review. --- and before anyone asks, this is my statement on CrowdStrike calling everyone disgruntled: "I'm not disgruntled. But as a shareholder (and probably more primarily, so…

I mourn the fact that your ex co-workers are still working for a shitty company.

The market for jobs isn't great, so i don't blame them.

At the same time, i feel like big profit-chasing software companies are all like how CrowdStrike is.

Many may be in the same type of company, but situations have not arisen that reveal how leadership really feels about employees.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#190
post #36

Found out that the CrowdStrike Mac agent (Falcon) sends all your secrets from environment variables to their cloud hosted SIEM. In plain text. Anyone with access to your CS SIEM can search for GitHub, aws, etc creds. Anything your devs, ops and sec teams use on their Macs. Only the Mac version does this. There is no way to disable this behaviour or a way to redact things. Another really odd design decision. They prob…

Having worked for a SIEM vendor, I can say that all security software is extremely invasive, and most security people can probably track every action you make on company-issued devices, and that includes HTTPS decryption.
Post reply on HN