Live data from Hacker News

CrowdStrike ex-employees: 'Quality control was not part of our process'

semafor.com

191–200 of 311 posts

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#191

Critical software infrastructure should be regulated the way critical physical infrastructure is. We don't trust the people who make buildings and bridges to "do the right thing" - we mandate it with regulations and inspections. (When your software not working strands millions of people around the globe, it's critical) And this was just a regular old "accident"; imagine the future, when a war has threat actors trying…

The regulations were the reason the companies were running Crowdstrike in the first place.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#192
post #38

Earlier quoted context omitted.

At some companies, like Boeing, the shorter list would be the gruntled employees.

> gruntled have never heard that word used is a non-negative way

Fun linguistics fact, but gruntled as the antonym of disgruntled is a back-formation. The word disgruntled is a bit strange, in that it uses "dis-" not as a reversal prefix (such as in dissatisfied or dissimilar), but as an intensifier. The original "gruntle" was related to grunt, grunting, it was similar to "grumble", denoting the sounds an annoyed crowd might make. But this old sense of gruntle, gruntling, gruntled has not been used since the 16th century. And in the past century, people have started back-forming a new "gruntle" by analyzing "dis-gruntled" as using the more common meaning of "dis-".

A similar use of dis- as an intensifier apparently happened in "dismayed" (here from an Old French verb, esmaier , which meant to trouble, to disturb), and in "disturbed" (from Latin a word, turba, meaning turmoil). I haven't heard any one say they are "mayed" or "turbed", but people would probably see the same as "gruntled" if you used them.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#193
post #36

Found out that the CrowdStrike Mac agent (Falcon) sends all your secrets from environment variables to their cloud hosted SIEM. In plain text. Anyone with access to your CS SIEM can search for GitHub, aws, etc creds. Anything your devs, ops and sec teams use on their Macs. Only the Mac version does this. There is no way to disable this behaviour or a way to redact things. Another really odd design decision. They prob…

Having worked for a SIEM vendor, I can say that all security software is extremely invasive, and most security people can probably track every action you make on company-issued devices, and that includes HTTPS decryption.

Reminds me of a guy I know openly bragging that he can watch all of his customers who installed his company's security cameras. I won't reveal his details but just imagine any cloud security camera company doing the same and you would probably be right.

I guess it's pretty much the same principle.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#194

Earlier quoted context omitted.

But that doesn't have anything to do with what UX designers typically do

the person you're replying will not take any sane argument once they decided that UX must be involved in kernel technical decision...

Pfft, I never said that at all. I’m not talking about technical decisions. OP was talking about QC, which is verifying software for human use. If you don’t have user-centered people involved (UX or product or proserve) then you end up with user-hostile decisions like these people made.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#195

Not justifying what they did with qc, but qc is missing from quite a few places in software development that I've been apart of. People might get the impression from the article that every software project is well tested, whereas in my experience most are rushed out.

I’ve worked for several multi billion dollar software companies. None of them had a dedicated QA function by design. Everything is about moving fast. That culture is ok if you’re making entertainment software or low criticality business software. It’s a very bad idea for critical software. Unfortunately the “move fast” attitude has metastasised to places where it has no place .

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#196
post #182

Earlier quoted context omitted.

I've worked in these enterprise organizations for a long time. They don't run on common sense, or even what one might consider "business sense". Their existing incentives create bizarre behavior. For example, you might think "if a big security exploit happens, the stock price might tank" . So if they value the stock price, they'll focus on security, right?. In reality what they do is focus on burying the evidence of…

While good, those ideas will all increase costs. Would you pay 10x (or more, even) for these systems? That means 10x the price of water, utilities, transport etc, which then accumulate up the chain to make other things which don't have criticality but do depend on the ones that do. The thing is, what exists today exists because it's the path of least resistence.

You're right (not sure about the exact factor though) - and there's also additional costs when those systems fail. Someone, somewhere lost money when all those planes were grounded and services suspended.

At some point - maybe it already happened, I don't know - spending more on preventive measures and maintenance will be the path of least resistance.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#197
post #40
post #24

Earlier quoted context omitted.

"Everyone" piles on Tesla all the time; a worthwhile comparison would be how Tesla roll out vehicle updates. Sometimes people are up in arms "where's my next version" (eg when adaptive headlights was introduced), yet Tesla prioritise a safe, slow roll out. Sometimes the updates fail (and get resolved individually), but never on a global scale. (None experienced myself, as a TM3 owner on the "advanced" update preferen…

You can also say the same thing about Google. Just go look at the release notes on the App Store for the Google Home app. There was a period of more than six months where every single release said "over the next few weeks we're rolling out the totally redesigned Google Home app: new easier to navigate 5-tab layout." When I read the same release notes so often I begin to question whether this redesign is really taking…

> Just go look at the release notes on the App Store for the Google Home app. [...] When I read the same release notes so often I begin to question whether this redesign is really taking more than six months to roll out.

Google is terrible at release notes. Since several years ago, the release notes for the "Google" app on the Android app store always shows the exact same four unchanging entries, loosely translating from Portuguese: "enhanced search page appearance", "new doodles designed for app experience", "offline voice actions (play music, enable Wi-Fi, enable flashlight) - available only in the USA", "web pages opened directly within the app". I heavily doubt it's taking these many years to roll out these changes; they probably simply don't care anymore, and never update these app store release notes.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#198
post #79
post #71

Earlier quoted context omitted.

Otherwise malware can hide in environment variables

Ok, suppose you're right. Why are they only doing it for macs then?

I don't think this is limited to just Macs based on my experience with the tool. It also sends command line arguments for processes which sometimes contain secrets. The client can see everything and run commands on the endpoints. What isn't sent automatically can be collected for review as needed.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#199
post #36

Found out that the CrowdStrike Mac agent (Falcon) sends all your secrets from environment variables to their cloud hosted SIEM. In plain text. Anyone with access to your CS SIEM can search for GitHub, aws, etc creds. Anything your devs, ops and sec teams use on their Macs. Only the Mac version does this. There is no way to disable this behaviour or a way to redact things. Another really odd design decision. They prob…

Anyone with the right level of access to your Falcon instance can run commands on your endpoints (using RTR) and collect any data not already being collected.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#200
post #163

Does anyone have a logical reason why this company should not be sued into oblivion?

Yes, because in point of fact this company is the best at what it does — preventing security breaches. The outage — disruptive as it was — was not a breach. This elemental fact is lost amidst all the knee jerk HN hate, but goes a long way toward explaining why the stock only took a modest hit.

That's a somewhat narrow definition of "security."

The 3rd component of the CIA triad is often overlooked, yet the availability is what makes the protected asset—and, transitively, the protection itself—useful at the first place.

The disruption is effectively a Denial of Service.

Post reply on HN