Live data from Hacker News

CrowdStrike ex-employees: 'Quality control was not part of our process'

semafor.com

51–60 of 311 posts

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#52
post #51

What are some alternatives to CrowdStrike?

Personal: Nothing - Windows Defender is built into Windows.

Business: Nothing - Windows Defender Advanced Threat Protection is built into the higher Microsoft 365 license tiers.

It amazes me people chose to pay money to have all their PCs bluescreen.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#53
post #43
post #36

Found out that the CrowdStrike Mac agent (Falcon) sends all your secrets from environment variables to their cloud hosted SIEM. In plain text. Anyone with access to your CS SIEM can search for GitHub, aws, etc creds. Anything your devs, ops and sec teams use on their Macs. Only the Mac version does this. There is no way to disable this behaviour or a way to redact things. Another really odd design decision. They prob…

Is this really a criticism? Because this has been the case forever with all security and SIEM tools. It’s one of the reasons why the SIEM is the most locked down pieces of software in the business. Realistically, secrets alone shouldn’t allow an attacker access - they should need access to infrastructure or a certificates in machines as well. But unfortunately that’s not the case for many SaaS vendors.

All SIEM instances certainly contain a lot of sensitive data in events, but I'm not sure if most agents forward all environment variables to a SIEM.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#54
If their (or your) shop is anything like mine, its' been a constant whittling of ancillary support roles (SDET, QA, SRE) and a shoving of all of the above into the sole responsibility of devs over the last few years. None of this is surprising at all.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#55
post #8

Earlier quoted context omitted.

There definitely was a huge outage, but based on the given information we still can't know for sure how much they invested in testing and quality control. There's always a chance of failure even for the most meticulous companies. Now I'm not defending or excusing the company, but a singular event like this can happen to anyone and nothing is 100%. If thorough investigation revealed poor quality control investment com…

Two things are clear though Nobody ran this update The update was pushed globally to all computers With that alone we know they have failed the simplest of quality control methods for a piece of software as widespread as theirs. This is even excluding that there should have been some kind of error handling to allow the computer to boot if they did push bad code.

> there should have been some kind of error handling

This is the point I would emphasize. A kernel module that parses configuration files must defend itself against a failed parse.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#56

Everything that we know about CrowdStrike stinks of Knight Capital to me. A minor culture problem snowballed into complete dysfunction, eventually resulting in a company-ending bug.

Knight Capitol: "$10 million a minute. That’s about how much the trading problem that set off turmoil on the stock market on Wednesday morning is already costing the trading firm. The Knight Capital Group announced on Thursday that it lost $440 million when it sold all the stocks it accidentally bought Wednesday morning because a computer glitch. " Glitch. Oh... https://en.wikipedia.org/wiki/Therac-25

I do not work in finance, but surely every trading company has had an algorithm go wild at some point. Just becomes a matter of how fast someone can pull the circuit breaker before the expensive failure becomes public.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#57
post #43
post #36

Found out that the CrowdStrike Mac agent (Falcon) sends all your secrets from environment variables to their cloud hosted SIEM. In plain text. Anyone with access to your CS SIEM can search for GitHub, aws, etc creds. Anything your devs, ops and sec teams use on their Macs. Only the Mac version does this. There is no way to disable this behaviour or a way to redact things. Another really odd design decision. They prob…

Is this really a criticism? Because this has been the case forever with all security and SIEM tools. It’s one of the reasons why the SIEM is the most locked down pieces of software in the business. Realistically, secrets alone shouldn’t allow an attacker access - they should need access to infrastructure or a certificates in machines as well. But unfortunately that’s not the case for many SaaS vendors.

> Because this has been the case forever with all security and SIEM tools.

Why?

There is no need to send your environment variables.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#58
post #48

Why would it matter? The absolute worst case scenario happened and their stock is still up 50% YoY, beating the S&P 500.

I thought you were joking. The stock market is incredible.

Everyone must realize that crowdstrike has a captive audience with no alternatives that can meet corporate compliance.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#59
post #38

> CrowdStrike disputed much of Semafor’s reporting I expect some ex-employees to be disgruntled and present things in a way that makes CroudStrike look bad. That happens with every company. BUT, CrowdStrike has ZERO credibility at this point. I don't believe a word they say.

At some companies, like Boeing, the shorter list would be the gruntled employees.

> gruntled

have never heard that word used is a non-negative way

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#60

Earlier quoted context omitted.

"We can't regulate the industry because then the US loses to China" or "regulation will kill the US competitive advantage!" responses I've had to suggesting the same and I just can't. But I agree with you 100%. If it's safety critical, it should be under even more scrutiny than other things, it shouldn't be left to self-regulating QA-like processes in profit seeking companies and has to have a bit more scrutiny befor…

> then the US loses to China Yeah it makes no sense. Was the US not losing to China when we own-goaled the biggest cybersecurity incident in history?

> then the US loses to China

Such a silly meme, too. Economics 101 China and USA would both benefit by halting the conflict and trading with each other

Post reply on HN