Live data from Hacker News

CrowdStrike will be liable for damages in France, based on the OVH precedent

thehftguy.com

41–50 of 285 posts

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#41

> "It is not an isolated incident. The same thing happened few weeks earlier with the CrowdStrike agent on Linux, nuking the system and there may be other occurrences before." Is there a link with this incident?

https://www.neowin.net/news/crowdstrike-broke-debian-and-roc...

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#43
post #33
post #20

Earlier quoted context omitted.

The number of US tech businesses that are surprised they need, or think they can ignore the need, to obey employment and data protection laws when working in other jurisdictions is simply bonkers.

Well, it'd be a lot easier if most US entities understood that M/d/yy(yy) format is rare, or that default to Frankenstein degrees is pretty much the same/awkward (even Microsoft reset their weather widget to F on regular basis). The root of issue, not understanding local laws/culture, is very similar - surrounded by a vast market/culture (US +Canada) dulls your senses for the rest of the globe.

I thought Frankenstein degrees was a clever complaint about us companies wanting degrees for tech jobs

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#44

Holy shit (hits the fan). For sure CrowdStrike will be held accountable in several countries, but I believe that some conclusions need to be drawn also from a customer/user perspective. - Is it reasonable to grant such privilege access to a piece of software that ultimately is a black box ? - Is it reasonable to put a Microsoft / Commercial / Closed source OS in critical infrastructure ? If not considered as critical…

> Is it reasonable to grant such privilege access to a piece of software that ultimately is a black box ?

According to Microsoft its not but they were forced to. Interesting how the EU executive is now getting mixed up in this saga: https://www.euronews.com/next/2024/07/23/european-commission...

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#45
post #20

Earlier quoted context omitted.

The number of US tech businesses that are surprised they need, or think they can ignore the need, to obey employment and data protection laws when working in other jurisdictions is simply bonkers.

It's not unusual in the US to assume the US are the only planet in the universe.

You mean self declared (rightfully or wrongfully) leaders of the free world? :)

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#46
post #9

I was aware of this being the case when dealing with consumers, but had assumed that because B2B contracts are assumed to be between 2 sophisticated parties that there is little legislative protection that could override the terms of the contract. My understanding of law is generally UK based, but I'm not aware of legislation what would supersede a contract term limiting liability when the event that created the liab…

As the article already states, in most jurisdictions you cannot void gross negligence liability in contracts. It will probably come down to that in those jurisdictions.

If they willfully did not implement staged rollouts that look like negligence to me but ianal. You kill canaries for a reason.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#47
post #22

I wonder what happens if the damages exceed whatever assets they have in France.

They have at least a B.V. with assets in the Netherlands and usually that one contains money for "tax reasons" (e.g. avoiding taxes), and they can lay claim on that.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#48
post #3

It's good to remind people that general liability waivers you often find with license agreements have no meaning outside of US jurisdiction if you're doing business in another jurisdiction.

I wonder if there is a site that covers common software license and has liability maps by country as to how much liability is waived based on the laws there.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#49
post #20

Earlier quoted context omitted.

The number of US tech businesses that are surprised they need, or think they can ignore the need, to obey employment and data protection laws when working in other jurisdictions is simply bonkers.

It's not unusual in the US to assume the US are the only planet in the universe.

Special mention of the expression “the west” which Americans like to use to mean the USA and some amorphous blob I don’t really want to think about but I’m going to pretend is exactly the same as the USA.

Re: CrowdStrike will be liable for damages in France, based on the OVH precedent

#50
post #23

The 10$ gift cards were just hilarious. How could they possibly expect anyone to take them seriously?

Not a lawyer, but the cynic in me assumes that it is legal bait: if someone at the company cashed the $10 gift card one could argue that compensation for damages has been accepted and no further liability applies. At least legally speaking, obviously this is completely morally bankrupt.

Any normal legal system should have an option for avoiding this, like "reasonable" compensation (reasonable would then be argued in court but I'm pretty sure you can find a lawyer who can argue a uber gift card is not).
Post reply on HN