Live data from Hacker News

CrowdStrike to Delta: Stop pointing at us

wsj.com

1–10 of 76 posts

Re: CrowdStrike to Delta: Stop pointing at us

#5

> CrowdStrike said Sunday that its liability is contractually capped at an amount in the “single-digit millions.” Companies handling critical infrastructure should face more scrutiny imo.

By more „scrutiny“ do you mean increase the liability cap?

Re: CrowdStrike to Delta: Stop pointing at us

#6

> CrowdStrike said Sunday that its liability is contractually capped at an amount in the “single-digit millions.” Companies handling critical infrastructure should face more scrutiny imo.

Crowdstrike is not handling critical infrastructure. Delta is.

The reality is the industry wants its cake and eat it too. No one forced Delta to buy a software which could force upgrades in their production fleet. They're a billion dollars company, and should put their big boys pants on.

Re: CrowdStrike to Delta: Stop pointing at us

#7

> CrowdStrike said Sunday that its liability is contractually capped at an amount in the “single-digit millions.” Companies handling critical infrastructure should face more scrutiny imo.

Compare that to the Colonial Pipeline ransomware hack, where a Russian group disabled critical infrastructure by accident and the Russian government intervened. Crowdstrike on the other hand - national infrastructure is taken out and no word from the agencies on how to prevent a re-run.

Re: CrowdStrike to Delta: Stop pointing at us

#8

I struggle to understand MSFTs liability here. Can anyone explain to me how Microsoft would be liable for Delta’s outage?

Not providing a way to inspect those data except from within kernel drivers (or whatever Windows calls them.) The huge HN thread about what happened weeks ago had some comments about Linux using eBPF to get the same kind of information Crowdstrike needs and Macs having another technology to do the same thing. In both cases the kernel won't crash and take down the machine. Of course it's possible to hog a machine from user space and make it unusable.

Re: CrowdStrike to Delta: Stop pointing at us

#9

I struggle to understand MSFTs liability here. Can anyone explain to me how Microsoft would be liable for Delta’s outage?

Alot of people are blaming MSFT for approving this kernel driver and allow kernel drivers like this to crash the system.

Re: CrowdStrike to Delta: Stop pointing at us

#10

I struggle to understand MSFTs liability here. Can anyone explain to me how Microsoft would be liable for Delta’s outage?

Maybe as an operating system that Delta purchased, its kernel should not crash when a 3rd party software receives a faulty update?
Post reply on HN