CrowdStrike Update: Windows Bluescreen and Boot Loops
401–410 of 1001 posts
Re: CrowdStrike Update: Windows Bluescreen and Boot Loops
#402I guess this article might need some updating soon: https://www.crowdstrike.com/resources/reports/total-economic...
Re: CrowdStrike Update: Windows Bluescreen and Boot Loops
#403Chances if Microsoft or Crowdstrike will be held liable for financial losses caused by this outage?
Zero. Exactly Zero.
Clearly you have never been involved in buying insurance or writing contracts for IT products/services.
Loss of contracts, profits, goodwill, economic loss, loss of data and all that jazz is excluded in whole or limited to a fixed monetary value.
It is known as indirect, consequential or special loss, damage or liability.
No lawyer worth their salt will let an IT product/service company draft a contract that does not have the above type of clause..
And good luck finding an insurance contract that will pay out for such losses, indeed most of them have conditions that state your contracts with customers must exclude or limit such losses.
Most software also has clauses excluding use in safety critical environments.
Re: CrowdStrike Update: Windows Bluescreen and Boot Loops
#404Re: CrowdStrike Update: Windows Bluescreen and Boot Loops
#405Re: CrowdStrike Update: Windows Bluescreen and Boot Loops
#406So CrowdStrike is deployed as third party software into the critical path of mission critical systems and then left to update itself. It's easy to blame CrowdStrike but that seems too easy on both the orgs that do this but also the upstream forces that compel them to do it. My org which does mission critical healthcare just deployed ZScaler on every computer which is now in the critical path of every computer startin…
You're conflating Risk and Impact, and you're not considering the target of that Risk and that Impact.
Failing an audit:
1. Risk: high (audits happen all the time)
2. Impact to business: minimal (audits are failed all the time and then rectified)
3. Impact to manager: high (manager gets dinged for a failing audit).
Compare with failing an actual threat/intrusion:
1. Risk: low (so few companies get hacked)
2. Impact to business: extremely high
3. Impact to manager: minimal, if audits were all passed.
Now, with that perspective, how do you expect a rational person to behave?
[EDIT: as some replies pointed out, I stupidly wrote "Risk" instead of "Odds" (or "Chance"). Risk is, of course, the expected value, which is probability X impact. My post would make a lot more sense if you mentally replace "Risk" with "probability".]
Re: CrowdStrike Update: Windows Bluescreen and Boot Loops
#407In terms of analysing risk factors to minimise something like this happening again, what are the factors at play here? A Crowdstrike update being able to blue-screen Windows Desktops and Servers. Whilst Crowdstrike are going to cop a potentially existential-threatening amount of blame, an application shouldn't be able to do this kind of damage to an operating system. This makes me think that, maybe, Crowdstrike were…
Re: CrowdStrike Update: Windows Bluescreen and Boot Loops
#408Re: CrowdStrike Update: Windows Bluescreen and Boot Loops
#409Re: CrowdStrike Update: Windows Bluescreen and Boot Loops
#410So CrowdStrike is deployed as third party software into the critical path of mission critical systems and then left to update itself. It's easy to blame CrowdStrike but that seems too easy on both the orgs that do this but also the upstream forces that compel them to do it. My org which does mission critical healthcare just deployed ZScaler on every computer which is now in the critical path of every computer startin…