10 ms·
Chances if Microsoft or Crowdstrike will be held liable for financial losses caused by this outage?
by novaRom 2y ago
Chances if Microsoft or Crowdstrike will be held liable for financial losses caused by this outage?
- rwmj 2y agoNone whatsoever, their contracts with customers will limit liability to the price paid for the software/subscription. If there was open-ended liability for software failures then very little software would get written.
- account42 2y agoThis is an insane take. Do you think other industries get away with limiting their liability to the product cost? No, because that doesn't provide adequate incentives for making a safe product. The amount of software that gets written depends mostly on the demand for that software. Even if Micrososft would not be willing to up their game to make the risk viable then someone else would.
- rwmj 2y agoThe thing is we know how to make (eg) food that is safe or to a lesser extent bridges that don't fall down. If you sell food that makes people sick you should have known how to avoid that and so you can be held liable. We don't have a good idea how to make software that is flawless, at least, not at scale for a cost that is acceptable. This is changing a little bit now with the drive by governments to use memory-safe languages, but that only covers a small part of the possible spectrum of bugs in software and hardware.
- Manfred 2y agoNothing is without flaws, it's about limiting risk to an acceptable amount. Critical software should be held against higher standards.
- rwmj 2y agoWhat's "critical software"? Software controlling flight systems in planes is already held to very high standards, but is enormously expensive to write and modify. In this case it seems most of the software which is failing is dull back office stuff running on Windows - billing systems, train signage, baggage handling - which no one thought was critical, and there's no way on earth we could afford to rewrite it in the same way as we do aircraft systems.
- Manfred 2y agoI meant critical software a short-hand for something like: quality of software should be proportional to the amount of disruption caused by downtime. Point of sale in a records store, less important. Point of sale in a pharmacy, could be problematic. Web shop customer call center, less important. Emergency services call center, could be problematic.
- burnished 2y agoWhat you're describing is a system where the degree of acceptable failure is determined after the software becomes a product because it is being determined by how important the buyer is. That is backwards and unworkable.
- kuboble 2y agoI think the system is rather a one where if you offer critical services then you're not allowed to use a software that hasn't been developed up to a particular high standard. So if you develop your compression library it can't be used by anyone running critical infra unless you stamp it "critical certified", which in turn will make you liable for some quality issues with your software.
- regularfry 2y agoIt isn't, though. "You may not sell into a situation that creates an unacceptable hazard" is essentially how hazardous chemical sale is regulated, and that's just the first example that I could find. It's not uncommon for a seller to have to qualify a buyer.
- llm_trw 2y agoWe don't know how to make general software safe, but we do know how to make any one piece of software safe. If you're software is going to be used as infrastructure then it should be held to the same standards. If you don't want it to be treated as infrastructure don't sell it to hospitals.
- deleted 2y ago[deleted]
- Reason077 2y agoIt doesn’t really matter what the contract says. Laws take precedence over contracts. For example, Boeing’s liability for 737 airliners that crash due to faulty software certainly isn’t limited to the price of the planes.
- YeBanKo 2y agoBut only $243.6M for fraud, which caused death of 346 people.
- anigbrowl 2y agoCrowdstrike's stock closed at $343 yesterday, I imagine that and MSFT are going to be cratering later this morning.
- dist-epoch 2y agoMSFT will be fine. They are riding the AI waves, this is not meaningful, especially since they are not at fault.
- Cthulhu_ 2y agoIt may not be their fault directly but it is causing Windows systems to bluescreen, which IS their fault and their responsibility, ultimately.
- hulitu 2y agoWindows blue screen was never Microsoft's responsibility. /s
- echoangle 2y agoHow is it their fault and responsibility? Isn’t falcon sensor basically running like a kernel module? Does it mean that Windows is not engineered properly when it can be crashed by this?
- wwtrv 2y agoAre you saying that they should prevent or limit the ability of their users from installing third party software? Or at the very least prevent it from running in kernel mode?
- rocqua 2y agoA more reasonable claim would be that microsoft should have a way to allow virus-scanners to run without needing to be able to crash the kernel. That isn't an easy thing to do, but it should be possible.
- ssss11 2y agoThat’s what the license agreement says. Wait till every man and his dog sues them.
- beejiu 2y agoCaveat to this: In the UK and many other countries, you cannot limit liabilities that cause death or personal injury arising from negligence.
- Cthulhu_ 2y agoYeah but if it's a hospital, they should be able to operate without these IT systems. Nothing critical / life-or-death / personal injury should rely on Windows / IT systems.
- SuperNinKenDo 2y agoWhy? Because you simply wish it to be so?
- Y_Y 2y agoBecause it's evidently a bad idea and there are reasonable alternatives.
- cqqxo4zV46cp 2y agoThat’s easy for you to say, with the benefit of recency bias, and with presumably zero experience in running a hospital.
- throwaway3306a 2y agoThat's not about experience, that's about following the regulated standards. This is well known ever since technology (not computers) got into hospitals.
- bdd8f1df777b 2y agoNone of the points you mention detracts from the correctness of his/her statement.
- SuperNinKenDo 2y ago
- citrin_ru 2y agoYes, software industry as we know would not exists if companies where held liable for all damages. But in the current state of affairs they have little incentive to improve software quality - when incident like this happens they can suffer an insignificant short term valuation loss but unless it happens too often they can continue businesses as usual. Many companies paying lip service to quality/reliability but internal incentives almost always go against maintenance and quality of service work (and instead reward new projects, features e. t. c.).
- josephg 2y ago> Yes, software industry as we know would not exists if companies where held liable for all damages. Of course it would. Restaurants are held liable for food poisoning, but they still operate just fine. They just - y’know - take care that they don’t poison their customers. If computer systems were held liable, software would be a lot more expensive. There would be less of it. And it would also be better. I think I can get behind that future.
- butlike 2y agoI like that future too, but to play devil's advocate: Write me software that coordinates all flights to and from airports, capturing all edge-cases, that's bug free. Then tell me the number you estimate and the number of years to roll this out.
- josephg 2y agoSure, but ... thats not a spec. Specs have clear goals and limited scope. "All flights from all airports forever" is impossible to program, full stop. The right way to write code like that is to start simple and small - we're going to service airports X, Y and Z. Those airports handle Q planes per day. The software will be used by (this user group) and have (some set of responsibilities). The software engineers will work with the teams on the ground during and after deployment to make sure the software is fit for purpose. Someone will sign off on using it and trusting its decisions. And lets also do a risk assessment where we lay out all the ways defects in the software could cost money and lives, so we can figure out how risk averse we need to be. Give me scope like that, and sure - I'll put a team together to write that code. It'll be expensive, but not impossible. And once its working well, I'd happily roll it out to more airports in a controlled and predictable manner.
- 0x1ceb00da 2y agoFrom windows tos: Disclaimer. Neither Microsoft, nor the device manufacturer or installer, gives any other express warranties, guarantees, or conditions. Microsoft and the devicemanufacturer and installerexclude all implied warranties and conditions, including those of merchantability, fitness for a particular purpose, and non-infringement. If your local law does not allow the exclusion of implied warranties, then any implied warranties, guarantees, or conditions last only during the term of the limited warranty and are limited as much as your local law allows. If your local law requires a longer limited warranty term, despite this agreement, then that longer term will apply, but you can recover only the remedies this agreement allows.
- moffkalast 2y ago"We give you no guarantees, unless the local law says we have to give them to you, in which case we do." So they might get sued on a local level?
- DaoVeles 2y agoHypothetically even if they were liable they would bankrupt before even a few percent of damages is recovered. You cannot pluck a bald chicken.
- llm_trw 2y agoThis is where public executions of executives help.
- lifeisstillgood 2y agoBut the Ticketmaster software would buckle under the strain :-)
- InsideOutSanta 2y ago>they would bankrupt before even a few percent of damages is recovered Wouldn't that be the desirable outcome, though? Given the amount of damage they have caused, they should cease to exist.
- hyperman1 2y agoA local rooflayer is absolutely corrupt. He cheats every customer, produces leaky roofs, doesn't even pay taxes completely. It takes 2 year for the legal system to catch up, at which point he starts a new company, bankrupts the old one, sells all his tools cheaply to the new company, and fires and rehires his workers. I've seen this game going on for 14 years now. I think Crowdstrike would do the same: Start a new one, sell the software, fire and rehire the workers, then go on as if nothing happened
- nyarlathotep_ 2y agoI'd call BS on this story, but I know a friend that bought a home a few years back from a homebuilder that did a similar thing, except at a whole home level. Absolute disaster. he's been chasing him for half a decade now via legal means to get things fixed.
- 2y ago
- maeil 2y agoFinancial losses? The comment you're replying to is mentioning heart attack treatment here. We're talking about deaths. Most of us won't like to hear this but for all of us who work at SaaS that is deployed on servers around the worlds, our bugs cause people to die. It's a given that at least a dozen people will die directly (medical flights, hospitals both being hit) due to this broken update, let alone indirectly.
- frereubu 2y agoI don't think the parent comment was ignoring that. The penalty for a company who does this can't be to bring someone back from the dead, it's likely to be financial, which is the aspect they're talking about.
- maeil 2y ago[flagged]
- kadoban 2y agoGood. That's the HN way.
- stavros 2y agoThat's how I read it, ie "will there be severe fines for the loss of life and other losses for this?".
- deleted 2y ago[deleted]
- SirGiggles 2y agoAs others have already stated, yes, that is how we should be interpreting comments, in good faith and in the most charitable way as the site guidelines suggests us to.
- cqqxo4zV46cp 2y ago
- kaliqt 2y agoYes, SLA. No one gets held liable if the legal is done correctly and there were no guarantees, but on cloud there is 100% SLA so they will pay out.
- Keyframe 2y agoHow about people in charge of choosing these clown solutions - both crowdstrike and windows?
- swarnie 2y agoIn your world i should switch my modest 1000 seats over to Linux desktops? I'm not sure how i'm going to explain the productivity loss and retraining costs to the board if im honest.
- jeroenhd 2y agoPlus, CrowdStrike runs on Linux as well. _This time_ they only crashed Windows devices, but there's no guarantee that switching to Linux would prevent any of it. You can switch away from CrowdStrike but I doubt you'll be able to convince whoever mandated CS to be installed to not install an alternative that carries exactly the same risks.
- whyoh 2y ago>CrowdStrike runs on Linux as well. _This time_ they only crashed Windows devices, but there's no guarantee that switching to Linux would prevent any of it. In fact there was a recent CrowdStrike-related crash in RHEL: https://old.reddit.com/r/crowdstrike/comments/1cluxzz/crowdstrike_kernel_panic_rhel_94/ https://old.reddit.com/r/crowdstrike/comments/1cluxzz/crowds... https://access.redhat.com/solutions/7068083 https://access.redhat.com/solutions/7068083
- ExoticPearTree 2y agoAt least on Linux it runs on eBPF sniffing so the chances of fudging something are lower. There are some supported Linux distributions where they also have a kernel module and there might a higher chance of that exploding.
- nolist_policy 2y agoNo you should switch over to Chromeos, iPads, ... anything but Microsoft. Crowdstrike only exists because Windows and other Microsoft products are so insecure their default configuration.
- traceroute66 2y ago> Chances if Microsoft or Crowdstrike will be held liable for financial losses caused by this outage? Zero. Exactly Zero. Clearly you have never been involved in buying insurance or writing contracts for IT products/services. Loss of contracts, profits, goodwill, economic loss, loss of data and all that jazz is excluded in whole or limited to a fixed monetary value. It is known as indirect, consequential or special loss, damage or liability. No lawyer worth their salt will let an IT product/service company draft a contract that does not have the above type of clause.. And good luck finding an insurance contract that will pay out for such losses, indeed most of them have conditions that state your contracts with customers must exclude or limit such losses. Most software also has clauses excluding use in safety critical environments.
- kvgr 2y agoThere will be no Crowdstrike left after this. I am just upset I cant short it…
- deleted 2y ago[deleted]
- odieldomanie 2y agoSome people in the comments claim CS was used for compliance reasons. Some others claim Windows & CS do not offer warranties. How can a product satisfy the compliance check-box, if it does not offer the warranty and not accept liability for the related features?
- Closi 2y agoWhile software is often warranted, contracts won't often accept liability in terms of business damages etc, and that's not usually a requirement for compliance. If it was, it would also make it impractical for a small business to contract with a large one because of risk.
- PretzelPirate 2y agoI dont think you can hold Microsoft liable for 3rd party software pushing its own update. Microsoft didn't make anyone install Crowdstrike or it's update files.
- btbuildem 2y agoPrison time for the CEO and board of directors would be nice. Enough of this limited liability nonsense, there need to be serious, severe, life-changing consequences.
- lenerdenator 2y agoDepends. I'm at an EMR maker; our Windows machines (as well of those of our clients - read: hospitals and doctors offices) are down. That is, of course, bad for the patients under their care. Do these clients have SLAs? If so, they're definitely on the hook for something. You could probably get a few businesses together for a decent class-action against Crowdstrike. You're then expecting a lawyer to be able to convince a dozen semi-random people with varying degrees of computer knowledge that Crowdstrike's software was negligently designed, developed, and deployed in a way that caused financial or life losses for customers. So, really, it's a coin flip.
- nubinetwork 2y agoWhat if your company mandated your customers run crowdstrike in order to run your software? What are the legal implications of that? Wouldn't that also put your contracts on the hook?
- ohwat 2y agoNegligence at Crowdstrike is not covered by any SLA. Even if insured, Crowdstrike could be fucked. Let alone, companies going to try and how much cost this has. Long term, their fucked.
- TheOne1001 2y agoDo we not remember "Ma" Bell?This should perhaps be a wakeup call in regards to Microsoft and other large tech having concentrated fingers in too many pies. This appears to be an anti-trust issue at its core. Was it really a botched update? Or was it a test run for holding the world hostage prior to a coup?
- Cotszy64 2y ago[flagged]