3 ms·
I’m pretty certain CS has contracts that limit their liabilities in events like this. Probably a refund is all they’ll be on the hook for. Sadly, damage done
by LASR 2y ago
I’m pretty certain CS has contracts that limit their liabilities in events like this.
Probably a refund is all they’ll be on the hook for.
Sadly, damage done like this is just chalked up to an accident, and swept under the rug.
- Terretta 2y ago> contracts that limit their liabilities… refund is all they’ll be on the hook for By cashing in this $10 Uber Eats coupon you agree to hold harmless... - https://news.ycombinator.com/item?id=41058261 https://news.ycombinator.com/item?id=41058261 - https://techcrunch.com/2024/07/24/crowdstrike-offers-a-10-apology-gift-card-to-say-sorry-for-outage/ https://techcrunch.com/2024/07/24/crowdstrike-offers-a-10-ap...
- mirashii 2y ago"A few people on twitter are saying this thing happened. We didn't actually talk to them, we didn't look at the emails and verify their authenticity ourselves, we just trusted some twitter screenshots and wrote a blogspam article stating it as truth. We put absolutely no critical thought into whether this was a likely thing, and we completely ignored the many government and media reports that are credibly sourced which state that there are known phishing scams and other threat actors trying to capitalize on this incident.” I highly doubt this is something that Crowdstrike actually did. Edit: Amazingly they did, the article has been updated with a statement. Amazingly stupid all around.
- vb-8448 2y agoIt depends on the actual root cause, gross negligence won't save them, regardless of what they put in the contracts. From my point of view, one of the greatest problem for them is that they bypassed customers deployment policies.
- sithadmin 2y ago>one of the greatest problem for them is that they bypassed customers deployment policies Caveat emptor. Falcon and other similar security products often push updates at-will, and they're fully transparent about this if you actually read the contract terms and understand the vendor's approach to operations. I have worked with many clients that elect not to use such tools in certain sensitive environments, specifically to mitigate the risk of being impacted by something like CrowdStrike's 7/19 event.
- abnercoimbre 2y agoDo we have more insight into the nature or reasons behind the bypassing?
- red-iron-pine 2y agorespond to threats faster. and without direct involvement of the owning company, since their GPO or other updaters / control systems may also be compromised.
- gruez 2y ago>From my point of view, one of the greatest problem for them is that they bypassed customers deployment policies. Do you really want to wait until for the weekly/monthly/quarterly deployment window to deploy a detection update for a 0day, or a new type of malware?