Critical software infrastructure should be regulated the way critical physical infrastructure is. We don't trust the people who make buildings and bridges to "do the right thing" - we mandate it with regulations and inspections. (When your software not working strands millions of people around the globe, it's critical) And this was just a regular old "accident"; imagine the future, when a war has threat actors trying…
CrowdStrike ex-employees: 'Quality control was not part of our process'
191–200 of 311 posts
Re: CrowdStrike ex-employees: 'Quality control was not part of our process'
#192Earlier quoted context omitted.
At some companies, like Boeing, the shorter list would be the gruntled employees.
> gruntled have never heard that word used is a non-negative way
A similar use of dis- as an intensifier apparently happened in "dismayed" (here from an Old French verb, esmaier , which meant to trouble, to disturb), and in "disturbed" (from Latin a word, turba, meaning turmoil). I haven't heard any one say they are "mayed" or "turbed", but people would probably see the same as "gruntled" if you used them.
Re: CrowdStrike ex-employees: 'Quality control was not part of our process'
#193Found out that the CrowdStrike Mac agent (Falcon) sends all your secrets from environment variables to their cloud hosted SIEM. In plain text. Anyone with access to your CS SIEM can search for GitHub, aws, etc creds. Anything your devs, ops and sec teams use on their Macs. Only the Mac version does this. There is no way to disable this behaviour or a way to redact things. Another really odd design decision. They prob…
Having worked for a SIEM vendor, I can say that all security software is extremely invasive, and most security people can probably track every action you make on company-issued devices, and that includes HTTPS decryption.
I guess it's pretty much the same principle.
Re: CrowdStrike ex-employees: 'Quality control was not part of our process'
#194Earlier quoted context omitted.
But that doesn't have anything to do with what UX designers typically do
the person you're replying will not take any sane argument once they decided that UX must be involved in kernel technical decision...
Re: CrowdStrike ex-employees: 'Quality control was not part of our process'
#195Not justifying what they did with qc, but qc is missing from quite a few places in software development that I've been apart of. People might get the impression from the article that every software project is well tested, whereas in my experience most are rushed out.
Re: CrowdStrike ex-employees: 'Quality control was not part of our process'
#196Earlier quoted context omitted.
I've worked in these enterprise organizations for a long time. They don't run on common sense, or even what one might consider "business sense". Their existing incentives create bizarre behavior. For example, you might think "if a big security exploit happens, the stock price might tank" . So if they value the stock price, they'll focus on security, right?. In reality what they do is focus on burying the evidence of…
While good, those ideas will all increase costs. Would you pay 10x (or more, even) for these systems? That means 10x the price of water, utilities, transport etc, which then accumulate up the chain to make other things which don't have criticality but do depend on the ones that do. The thing is, what exists today exists because it's the path of least resistence.
At some point - maybe it already happened, I don't know - spending more on preventive measures and maintenance will be the path of least resistance.
Re: CrowdStrike ex-employees: 'Quality control was not part of our process'
#197Earlier quoted context omitted.
"Everyone" piles on Tesla all the time; a worthwhile comparison would be how Tesla roll out vehicle updates. Sometimes people are up in arms "where's my next version" (eg when adaptive headlights was introduced), yet Tesla prioritise a safe, slow roll out. Sometimes the updates fail (and get resolved individually), but never on a global scale. (None experienced myself, as a TM3 owner on the "advanced" update preferen…
You can also say the same thing about Google. Just go look at the release notes on the App Store for the Google Home app. There was a period of more than six months where every single release said "over the next few weeks we're rolling out the totally redesigned Google Home app: new easier to navigate 5-tab layout." When I read the same release notes so often I begin to question whether this redesign is really taking…
Google is terrible at release notes. Since several years ago, the release notes for the "Google" app on the Android app store always shows the exact same four unchanging entries, loosely translating from Portuguese: "enhanced search page appearance", "new doodles designed for app experience", "offline voice actions (play music, enable Wi-Fi, enable flashlight) - available only in the USA", "web pages opened directly within the app". I heavily doubt it's taking these many years to roll out these changes; they probably simply don't care anymore, and never update these app store release notes.
Re: CrowdStrike ex-employees: 'Quality control was not part of our process'
#198Earlier quoted context omitted.
Otherwise malware can hide in environment variables
Ok, suppose you're right. Why are they only doing it for macs then?
Re: CrowdStrike ex-employees: 'Quality control was not part of our process'
#199Found out that the CrowdStrike Mac agent (Falcon) sends all your secrets from environment variables to their cloud hosted SIEM. In plain text. Anyone with access to your CS SIEM can search for GitHub, aws, etc creds. Anything your devs, ops and sec teams use on their Macs. Only the Mac version does this. There is no way to disable this behaviour or a way to redact things. Another really odd design decision. They prob…
Re: CrowdStrike ex-employees: 'Quality control was not part of our process'
#200Does anyone have a logical reason why this company should not be sued into oblivion?
Yes, because in point of fact this company is the best at what it does — preventing security breaches. The outage — disruptive as it was — was not a breach. This elemental fact is lost amidst all the knee jerk HN hate, but goes a long way toward explaining why the stock only took a modest hit.
The 3rd component of the CIA triad is often overlooked, yet the availability is what makes the protected asset—and, transitively, the protection itself—useful at the first place.
The disruption is effectively a Denial of Service.