Live data from Hacker News

CrowdStrike ex-employees: 'Quality control was not part of our process'

semafor.com

91–100 of 311 posts

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#91
post #80
post #44

Earlier quoted context omitted.

But why only forced on MacOS? I think some configurability would be great. I would like to provide an allow list or the ability to redact. Or exclude specific host groups. We all have different levels of acceptable risk

Conspiracy theory time. Because Apple is the only OS company that has reliably proven that it won't decrypt hard drives at government request.

This is a true conspiracy .

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#92
post #48

Why would it matter? The absolute worst case scenario happened and their stock is still up 50% YoY, beating the S&P 500.

I thought you were joking. The stock market is incredible. Everyone must realize that crowdstrike has a captive audience with no alternatives that can meet corporate compliance.

Can't think of a bigger flex of how locked-in their market share is.

On the plus side this should spur some disruptors into gear, assuming VCs are willing to pivot from wasting money funding LLM wrappers.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#93
post #83

Critical software infrastructure should be regulated the way critical physical infrastructure is. We don't trust the people who make buildings and bridges to "do the right thing" - we mandate it with regulations and inspections. (When your software not working strands millions of people around the globe, it's critical) And this was just a regular old "accident"; imagine the future, when a war has threat actors trying…

Did you notice that the piece of software in question was apparently installed mostly in companies where regulations and inspections already override sysadmins' common sense? Are you sure the answer is simply more of the same?

It’s not true that “common sense” is being overridden: most companies and sysadmins do need that baseline to avoid “forgetting” about things which aren’t trivial to implement (if you didn’t work in the field 10+ years ago, it was common to see systems getting patched annually or worse, people opening up SSH/Remote Desktop to the internet for convenience, shared/short passwords even for privileged accounts, vendors would require horribly insecure configuration because they didn’t want to hire anyone who knew how to do things better, etc.). There are drawbacks to compliance security but it has been useful for flushing all of that mess out.

Even if it wasn’t wrong, that’s still the wrong reaction. We’re in this situation because so many companies were negligent in the past and the status quo was obviously untenable. If there is a problem with a given standard the solution is to make a better system (e.g. like Apple did) rather than to say one of the most important industries in the world can’t be improved because that’d require a small fraction of its budget.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#94
post #2

> “Speed was the most important thing,” said Jeff Gardner, a senior user experience designer at CrowdStrike who said he was laid off in January 2023 after two years at the company. “Quality control was not really part of our process or our conversation.” This type of article - built upon disgruntled former employees - is worth about as much as the apology GrubHub gift card. Look, I think just as poorly about CrowdStr…

Well they certainly don't care about the speed of the endpoints their malware runs on. Shit has ruined my macos laptop's performance.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#95
post #2

> “Speed was the most important thing,” said Jeff Gardner, a senior user experience designer at CrowdStrike who said he was laid off in January 2023 after two years at the company. “Quality control was not really part of our process or our conversation.” This type of article - built upon disgruntled former employees - is worth about as much as the apology GrubHub gift card. Look, I think just as poorly about CrowdStr…

Honestly, this article describes nearly all companies (from the perspective of the engineers) so I’m not sure I find it hard to believe this one is the same.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#96

Earlier quoted context omitted.

There definitely was a huge outage, but based on the given information we still can't know for sure how much they invested in testing and quality control. There's always a chance of failure even for the most meticulous companies. Now I'm not defending or excusing the company, but a singular event like this can happen to anyone and nothing is 100%. If thorough investigation revealed poor quality control investment com…

> If thorough investigation revealed poor quality control investment compared to what would be appropriate for a company like this, then we can say for sure. We don't really need that thorough of an investigation. They had no staged deploys when servicing millions of machines. That alone is enough to say they're not running the company correctly.

Nonsense. You don’t need any staged deploys if you simply make no mistakes.

/s

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#98
post #2

> “Speed was the most important thing,” said Jeff Gardner, a senior user experience designer at CrowdStrike who said he was laid off in January 2023 after two years at the company. “Quality control was not really part of our process or our conversation.” This type of article - built upon disgruntled former employees - is worth about as much as the apology GrubHub gift card. Look, I think just as poorly about CrowdStr…

I just don't think a company like Crowdstrike has a leg to stand on when leveling the "disgruntled" label in the face of their, let's face it, astoundingly epic fuck up. It's the disgruntled employees that I think would have the most clear picture of what was going on, regardless of them being in QA/QC or not because they, at that point, don't really care any more and will be more forthright with their thoughts. I'd…

Why would you trust a company no-man any more than a company yes-man? They both have agendas and biases. Is it just that you personally prefer one set of biases (anti-company) more than the other (pro-company)?

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#99
post #43

Earlier quoted context omitted.

Is this really a criticism? Because this has been the case forever with all security and SIEM tools. It’s one of the reasons why the SIEM is the most locked down pieces of software in the business. Realistically, secrets alone shouldn’t allow an attacker access - they should need access to infrastructure or a certificates in machines as well. But unfortunately that’s not the case for many SaaS vendors.

Keeping secrets and other sensitive data out of your SIEM is a very important part of SIEM design. Depending on what you’re dealing with you might want to tokenize it, or redact it, but you absolutely don’t want to don’t want to just ingest them in plaintext. If you’re a PCI company then ending up with a credit card number in your SIEM can be a massive disaster. Because you’re never allowed to store that in plaintext…

> But I have no idea what they’d do if your SIEM somehow became full of credit card numbers, that probably is unfixable…

You'd get rid of it.

Re: CrowdStrike ex-employees: 'Quality control was not part of our process'

#100
post #20

Most interesting quote in the article: “It was hard to get people to do sufficient testing sometimes,” said Preston Sego, who worked at CrowdStrike from 2019 to 2023. His job was to review the tests completed by user experience developers that alerted engineers to bugs before proposed coding changes were released to customers. Sego said he was fired in February 2023 as an “insider threat” after he criticized the comp…

> Imagine criticizing a policy and then getting labeled "insider threat".

Especially because that’s incredibly dumb. A true insider threat would play nice while you find all your confidential data leaking.

Post reply on HN