CrowdStrike ex-employees: 'Quality control was not part of our process'
51–60 of 311 posts
Re: CrowdStrike ex-employees: 'Quality control was not part of our process'
#52What are some alternatives to CrowdStrike?
Business: Nothing - Windows Defender Advanced Threat Protection is built into the higher Microsoft 365 license tiers.
It amazes me people chose to pay money to have all their PCs bluescreen.
Re: CrowdStrike ex-employees: 'Quality control was not part of our process'
#53Found out that the CrowdStrike Mac agent (Falcon) sends all your secrets from environment variables to their cloud hosted SIEM. In plain text. Anyone with access to your CS SIEM can search for GitHub, aws, etc creds. Anything your devs, ops and sec teams use on their Macs. Only the Mac version does this. There is no way to disable this behaviour or a way to redact things. Another really odd design decision. They prob…
Is this really a criticism? Because this has been the case forever with all security and SIEM tools. It’s one of the reasons why the SIEM is the most locked down pieces of software in the business. Realistically, secrets alone shouldn’t allow an attacker access - they should need access to infrastructure or a certificates in machines as well. But unfortunately that’s not the case for many SaaS vendors.
Re: CrowdStrike ex-employees: 'Quality control was not part of our process'
#54Re: CrowdStrike ex-employees: 'Quality control was not part of our process'
#55Earlier quoted context omitted.
There definitely was a huge outage, but based on the given information we still can't know for sure how much they invested in testing and quality control. There's always a chance of failure even for the most meticulous companies. Now I'm not defending or excusing the company, but a singular event like this can happen to anyone and nothing is 100%. If thorough investigation revealed poor quality control investment com…
Two things are clear though Nobody ran this update The update was pushed globally to all computers With that alone we know they have failed the simplest of quality control methods for a piece of software as widespread as theirs. This is even excluding that there should have been some kind of error handling to allow the computer to boot if they did push bad code.
This is the point I would emphasize. A kernel module that parses configuration files must defend itself against a failed parse.
Re: CrowdStrike ex-employees: 'Quality control was not part of our process'
#56Everything that we know about CrowdStrike stinks of Knight Capital to me. A minor culture problem snowballed into complete dysfunction, eventually resulting in a company-ending bug.
Knight Capitol: "$10 million a minute. That’s about how much the trading problem that set off turmoil on the stock market on Wednesday morning is already costing the trading firm. The Knight Capital Group announced on Thursday that it lost $440 million when it sold all the stocks it accidentally bought Wednesday morning because a computer glitch. " Glitch. Oh... https://en.wikipedia.org/wiki/Therac-25
Re: CrowdStrike ex-employees: 'Quality control was not part of our process'
#57Found out that the CrowdStrike Mac agent (Falcon) sends all your secrets from environment variables to their cloud hosted SIEM. In plain text. Anyone with access to your CS SIEM can search for GitHub, aws, etc creds. Anything your devs, ops and sec teams use on their Macs. Only the Mac version does this. There is no way to disable this behaviour or a way to redact things. Another really odd design decision. They prob…
Is this really a criticism? Because this has been the case forever with all security and SIEM tools. It’s one of the reasons why the SIEM is the most locked down pieces of software in the business. Realistically, secrets alone shouldn’t allow an attacker access - they should need access to infrastructure or a certificates in machines as well. But unfortunately that’s not the case for many SaaS vendors.
Why?
There is no need to send your environment variables.
Re: CrowdStrike ex-employees: 'Quality control was not part of our process'
#58Why would it matter? The absolute worst case scenario happened and their stock is still up 50% YoY, beating the S&P 500.
Everyone must realize that crowdstrike has a captive audience with no alternatives that can meet corporate compliance.
Re: CrowdStrike ex-employees: 'Quality control was not part of our process'
#59> CrowdStrike disputed much of Semafor’s reporting I expect some ex-employees to be disgruntled and present things in a way that makes CroudStrike look bad. That happens with every company. BUT, CrowdStrike has ZERO credibility at this point. I don't believe a word they say.
At some companies, like Boeing, the shorter list would be the gruntled employees.
have never heard that word used is a non-negative way
Re: CrowdStrike ex-employees: 'Quality control was not part of our process'
#60Earlier quoted context omitted.
"We can't regulate the industry because then the US loses to China" or "regulation will kill the US competitive advantage!" responses I've had to suggesting the same and I just can't. But I agree with you 100%. If it's safety critical, it should be under even more scrutiny than other things, it shouldn't be left to self-regulating QA-like processes in profit seeking companies and has to have a bit more scrutiny befor…
> then the US loses to China Yeah it makes no sense. Was the US not losing to China when we own-goaled the biggest cybersecurity incident in history?
Such a silly meme, too. Economics 101 China and USA would both benefit by halting the conflict and trading with each other