12 ms·
CrowdStrike representatives issue trademark infringement notice to ClownStrike
- insane_dreamer 2y agoThat video is genius.
- Rothnargoth 2y agoHope they implement a link shortener on that domain with the endpoint "/deploy/patch/globally/unchecked/<uuid>".
- AHOHNMYC 2y agoFair parody user script response: // ==UserScript== // @name Clownin' // @namespace Clown Division // @include * // @version 0.0.1 // @author AHOHNMYC // ==/UserScript== /* This is also parody, like one in https://clownstrike.lol/crowdmad */ [ {'original': 'crowdstrike', 'parody': 'ClownStrike'}, ].forEach(clown => { tw = document.createTreeWalker(document, NodeFilter.SHOW_TEXT, el => el.textContent.toLowerCase().includes(clown['original'])); while(tw.nextNode()) tw.currentNode.textContent = tw.currentNode.textContent.replaceAll(new RegExp(clown['original'], 'ig'), clown['parody']) });
- deleted 2y ago[deleted]
- dmitrygr 2y agoSee also: https://en.wikipedia.org/wiki/Streisand_effect https://en.wikipedia.org/wiki/Streisand_effect
- actionfromafar 2y agoIt's hard to top the attention they already got though. From specialised vendor to house-hold name.
- xanderlewis 2y agoDo not click the link above. Its viewing has been officially outlawed. I’m warning you. Do not look.
- kurthr 2y agoWell, if you don't protect your trademark? It was how most people at M$ were referring to them last week. edit: OMG, I thought it would be obvious I'm kidding. I guess garbage HN comments win garbage HN prizes. Maybe there will be a supreme court ruling that George Kurtz has to wear a clown nose due to the Krusty precedent?
- jjulius 2y agoThere's "protecting your trademark from genuine copyright infringement" [nods], and "trying to silence legal parody via weak trademark arguments" [shakes head].
- hn_acker 2y ago> There's "protecting your trademark from genuine copyright infringement" You mean "genuine trademark infringement".
- jjulius 2y agoTouché, thank you!
- lcnPylGDnU4H9OF 2y agoTo be fair, they actually sent a copyright infringement notice for this alleged trademark infringement. You were just describing their behavior!
- sophacles 2y agoTo be fair, a trademark logo is also copyright protected... It's art. If crowdstrike lost the trademark, they'd still own the copyright on that logo.
- jsheard 2y agoCrowdStrike/CSC has owned at least clownstrike.com and clownstrike.net since 2012, but they weren't on the ball with those new TLDs it seems.
- Avicebron 2y agoI get it, staying on the ball in fast-changing dynamic environments can be tough, good thing they don't run an EDR
- scintill76 2y agoTheir TLD scraper created a file of nothing but zeroes, so the registration script crashed and went into a bootloop trying to read it.
- xanderlewis 2y agoIt’s quite surprising to me that they thought to do that, although maybe I’m just naive. I wonder what other parody names and altered versions they own…
- jsheard 2y agoCSCs whole deal is securing domain names for huge brands, they probably have people whose job involves thinking of derogatory domains like that so they can grab them pre-emptively. The people behind the .sucks TLD turned that into an incredible grift, they charge an exorbitant amount (about $300 a year) because they know every big brand will buy brand.sucks no matter what.
- SXX 2y ago.sucks TLD sounds like genious idea made real. http://microsoft.sucks http://microsoft.sucks redirect to Microsoft.com and they pay for it.
- popcalc 2y ago.EXPOSED operates on the same premise. And a lot of these gTLDs are run by groups of the same shady guys based out of Cyprus and Hong Kong.
- hatsunearu 2y agothat's really pathetic. they should own up to the mistake
- deleted 2y ago[deleted]
- Alupis 2y ago> they should own up to the mistake They did! They issued $10 Uber Eats Gift Certificates that were revoked minutes later[1]. What, you didn't get to use yours in time? [1] https://news.ycombinator.com/item?id=41058261 https://news.ycombinator.com/item?id=41058261
- subpub47 2y agoSurely those resources could be better spent on functional Uber Eats gift cards.
- tonetegeatinst 2y agoI heard they canceled the gift cards or they didn't work.
- ganeshkrishnan 2y agoThis is preposterous! I already ordered chicken chowmein with it
- deleted 2y ago[deleted]
- new299 2y agoI wonder to what extent companies consider the reputational damage these kinds of enforcement actions cause. I recently came across this when googling for information on a small Biotech startup: https://udrp.adr.eu/decisions/detail?id=65fab3e46fc02956a01040a9 https://udrp.adr.eu/decisions/detail?id=65fab3e46fc02956a010... Will probably be the first thing I remember when I hear their name.
- fxtentacle 2y agoOh wow, they sued someone who used his last name as a domain name because they feel like their trademark should allow them to prohibit him from using his family name ... And obviously they registered their trademark after he started using his name.
- cowsandmilk 2y ago> And obviously they registered their trademark after he started using his name. Actually, the company’s trademarks are from 2017 and he got his name via marriage in 2020. Still a stupid suit
- freehorse 2y agoYes, but they registered it in 2022, which makes the case even more hopeless.
- bitwize 2y agoPrince Rogers Nelson's given name was a registered trademark of Warner Music. It took that whole stunt with him changing his name to Love Symbol #2 to get them to relent.
- fuzztester 2y agowow. i didn't know that prince was the same as prince rogers nelson (only vaguely remembered the name prince as a musician from dances at high school), so googled his name: https://en.m.wikipedia.org/wiki/Prince_(musician) https://en.m.wikipedia.org/wiki/Prince_(musician)
- AcerbicZero 2y agoMust be contract renewal time, and they're rushing to pad the numbers ;)
- mmaunder 2y agoThis is why you want to remove as many intermediaries between your content and your audience as possible. Ideal scenario is your own ASN and a pipe with a commit and your own physical box. The only takedown target is your upstream bandwidth provider. From there you’re adding takedown targets: hosting provider, edge cache/firewall provider, commercial CMS, etc. So pick your middle ground carefully. I’d suggest that choosing a commercial CMS makes you an easy target. Apparently so does choosing Cloudflare.
- actionfromafar 2y agoNext up - Cloudstrike.com?
- SXX 2y agoAirStrike.com - considering downtime of so many airlines.
- airstrike 2y agoSadly I know from personal experience that that's been registered for a long time...
- readyplayernull 2y agoClownflare.com https://news.ycombinator.com/item?id=41132328#41133504 https://news.ycombinator.com/item?id=41132328#41133504
- nvy 2y agoCloudflare only stands up to bullies when the CEO feels personally attacked.
- fortran77 2y agoMore like ״caves in to bullies.”
- jojobas 2y ago
- asdefghyk 2y agoHow would I find these other ClownStrike parody sites ?
- tamimio 2y agoSomeone should make an awesome list!
- EADDRINUSE 2y agoIronically the site takes me back in time to the Attrition era, where sites like these were used as defacement to point out similar clownishness. Well done.
- mistercow 2y ago> I’m most definitely not trying to put CloudFlare in the middle on this… so I told CloudFlare that I will take the site off of CloudFlare; however, it is staying on the internet… I mean that’s kind, but the whole point of DMCA safe harbor provisions is that they aren’t in the middle of this. They send along the notice, you file a counter notice, and that’s it for their involvement, yeah? If CrowdStrike wants to press the issue, they go after you, not CloudFlare.
- insane_dreamer 2y agoYeah but you don't want to keep getting emails from Cloudflare or have them kick you off anyway since they don't want to keep getting emails either.
- akira2501 2y agoI think he's attempting to point out that CloudFront's basic value proposition is meaningless if a random third party company can automatically destroy your websites with a single letter. Worse still, the letter is obviously incorrect for a trademark dispute, possibly illegal as a result, and should have never made it to the customer before being reviewed or followed up on by internal staff. My read was "sorry you guys don't want to do your job so I'll just take my business elsewhere. goodbye."
- tgsovlerkhgsel 2y agoIn the meantime, though, even if you submitted a counter-notice, your content gets taken down for 14 days. That's likely why he migrated away.
- ronsor 2y agoJudging by the amount of upvotes this post has received, I believe CrowdStrike has made a major PR mistake.
- nerdponx 2y agoWho cares if it doesn't hurt revenue?
- rainsford 2y agoI certainly don't want to claim everyone on Hacker News is a high powered CISO making EDR purchasing decisions for their Fortune 500 company or whatever, but I feel like there are enough people with actual influence who read this site that if I was a security company (or any tech company) I wouldn't want front page stories that make me look petty about getting rightly clowned on after a fuck-up of galactic proportions.
- WheatMillington 2y agoI mean... is THIS going to be the thing to tip you over the edge? Not last month's shenanigans, but THIS?
- NohatCoder 2y agoThere is the difference that this mistake is much simpler. A lot of business people will understand that having a litigation team without even the most basic Streisand filter is a newbie mistake. How they should have/could have protected themselves against the big breakdown is a lot more complicated, even for tech people.
- subpub47 2y agoSeriously. If the last 20 years of fuckery haven't been enough, nothing short of a nuclear holocaust will make people stop and reconsider.
- hot_gril 2y ago
- swayvil 2y agoThey'll change their company name inside a year. Bet on it.
- MarkusQ 2y agoCrowdStrike definitely has the chops when it comes to taking sites down, I'll give them that.
- eftychis 2y agoI guess this site is using Linux or BSD and they had to venture outside their usual modus operandi to DMCA... /s
- zitterbewegung 2y agoOr a Mac. Also, I think kernel module like systems on macOS (ktext) got eliminated from current versions.
- throwup238 2y agoDid they try to misformat the DMCA take down notice in the hope that it takes down Cloduflare's parser? That sounds like something they would do.
- rhabarba 2y agoDon't forget that Clownstrike took down Linux systems in April.
- indigodaddy 2y agoFalcon sensor has been causing kernel panics / memory stacktraces / and insanely high load for years on Linux boxes (RHEL 7/8 mostly where I was at), not just in April.
- rhabarba 2y agoAh, I did not hear about that before. Thank you.
- Natsu 2y agoThey are quite capable of taking down Linux servers too: https://www.techspot.com/news/103899-crowdstrike-also-broke-debian-rocky-linux-earlier-year.html https://www.techspot.com/news/103899-crowdstrike-also-broke-...
- cj 2y agoFWIW: CSC is a company that other companies hire to act on its behalf. It's very likely that the company you work for uses CSC as it's registered agent in the State of Delaware for administrative purposes (CSC doesn't really do anything other than exist on paper and file annual forms to satisfy legal and compliance requirements necessary for companies to exist in the US). I wasn't aware they file DMCA requests on behalf of companies... that seems off brand for them. (After writing the above) turns out CSC has a Online Brand Protection service. https://www.cscdbs.com/en/brand-protection/ https://www.cscdbs.com/en/brand-protection/ I wouldn't be surprised if: 1) Crowdstrike incident takes down internet 2) Crowdstrike files a claim on their cyber insurance policy which includes coverage for brand protection 3) Crowdstrike (or their insurance company) buys some brand protection service, like the one offered by CSC 4) This guy receives a takedown When I started writing this comment I was intending to defend CSC. But after googling I think CSC's brand protection services are to blame. Seems to be having the opposite effect for Crowdstrike considering they paid to have their brand "protected" and now this guy's site is getting lots of traffic!
- freehorse 2y agoThey also apparently own the clownstrike.com domain [0] and this is since 2012, crowdstrike itself exists since 2011, so they must have hired them since close to the beginning. But could be that now they are probed to do damage control after the incident (though as always this tactic tends to disperse more damage than control it). [0] https://www.whois.com/whois/clownstrike.com https://www.whois.com/whois/clownstrike.com
- aragonite 2y agoReminds me of that time when Mike Bloomberg's lawyers preemptively registered 400 .nyc domains for him, apparently without his knowledge, many of which are hilariously negative (MikeIsTooShort.nyc, MikeBloombergIsADweeb.nyc, GetALifeMike.nyc etc.): https://www.huffpost.com/entry/michael-bloomberg-nyc-domain-fail_n_6101416/amp https://www.huffpost.com/entry/michael-bloomberg-nyc-domain-...
- batch12 2y agoI bet that brainstorming session was a blast
- bhartzer 2y agoWhat I don't understand is why companies and brands like this just don't use NameBlock or a similar domain blocking service like GlobalBlock. They literally can block domain names that have their company name or brand in them from being registered (up to 500 variations of their domain). It's literally like $99/year to place a block. Saves a lot of the hassle of having to deal with parody and phishing sites and trying to take them down. Just block the domain(s) from being registered in the first place.
- 0x1ch 2y agoYou'd be surprised. I recently parked some big name domains ending in various common TLDs in the world of government contracting. They did utilize some sort of parking or service to do it for them, but certainly not enough.
- voltaireodactyl 2y agoHow does that work in practice? Are you just paying them to lease it so you don’t have to?
- bhartzer 2y agoIf you place a block on a brand/companyname (a string of characters), then no one can register a domain name that contains those strings of characters. They also block up to 500 variations (placing a block on 'paypal' would get 'paypa1' blocked as well. Those domains that are blocked won't be 'parked', someone trying to register the domain that's blocked, it will just say it's not available for registration.
- cortesoft 2y agoI don't think you could block "clown" or "strike".
- bhartzer 2y agoYes, they could place a domain block on "crowdstrike", and variations of that would be blocked, such as cr0wdstrike, crowdstr1ke, etc.
- 486sx33 2y agoCrowdstrike is evil !
- insane_dreamer 2y agoIf they could just get you to install Falcon on your server, they wouldn't need the DMCA to take your site down ;)
- nicce 2y agoAbsolutely the most hilarious thing I have seen for a while. Thank you.
- insane_dreamer 2y agoThe only way to prevent this from happening again (by CloudStrike or a future incompetent company) is for CloudStrike to be sued out of existence.
- hot_gril 2y agoEh, there's a point where the parody is angrier and less funny than the subject, and this is well past that. Someone has too much time on their hands.
- neilv 2y agoCrowdStrike is arguing that their customers might mistake "ClownStrike" for their brand?
- deleted 2y ago[deleted]
- Subsentient 2y agoI am delighted to inform CrowdStrike that they have just done additional, extensive, damage to their brand, and will no doubt have just emboldened those who were tempted to sue them. Your unethical behavior and abuse of the DMCA will be used to punish you. If you succeed in getting ClownStrike taken down, you will be hated even more. Have fun annihilating your brand, reputation, and customer/industry trust and goodwill.
- hcfman 2y agoSometimes companies completely change their name after reputation damage. Maybe they are attacking clownstrike because they had intentions of escaping reputational damage by changing their name to clownstrike ?
- hcfman 2y agoIf clownstrike is taken, maybe they can try clownstruck?
- hcfman 2y agoWould I get sued if I made a company called clownstruck? There's quite a lot of difference, unless they really identify with the sentiment.
- stderr_on 2y agoyou can get sued if you use their logo/trademark/symbol to create your trademark!
- hcfman 2y agoWould clownstrikken be okay ?
- hcfman 2y agoPerhaps coulro-strike ?
- willguest 2y ago'antifraud.response@cscglobal.com' doesn't seem to understand what fraud is, which is more than a little concerning
- xyst 2y agoLawyers making bank on the billables for these bullshit DMCA claims. Unless it’s their internal/inhouse submitting these claims. The brand/rep of crowdstrike is already tarnished. Why let the pain continue via the Barbara Streisand effect? Not only are they technically incompetent, but now they are also petty. Poor decision making to be honest. (note: “csc” also owns crowdstrike.sucks and clownstrike.sucks)
- tomxor 2y agoClownprotection. "We are the clowns behind clowns, we file baseless DMCAs so you don't have to" "Just sit back and watch Barbra the clown do all the heavy lifting to destroy what's left of your already tainted brand".
- discordance 2y agoHow does CrowdStrike even have a business left to defend? Are companies still using their service?
- bigstrat2003 2y agoYes, of course there are. They may yet lose their customer base, but it takes more than a week or two for customers to jump ship en masse.
- hot_gril 2y agoI'm surprised their stock didn't fall further. Would think user trust is everything for this kind of company. Maybe it goes to show how numb a lot of traditional companies are to computer downtime.
- wanderingmind 2y agoStreisand effect in full play. Many people even in HN might not have known this parody site before, but will now know and actively engage with it. It's a shame people running these multi hundred billion dollar industries, never seem to learn basic unintended consequences of actions in socio-economic dynamics.
- failrate 2y agoIf they want it down, they just need to convince that website to use CrowdStrike.
- mococa 2y agoThe attempt to silence will likely backfire; the site will become famous.
- INGSOCIALITE 2y agothey are also sending dmca notices to etsy to take down parody stickers
- dh2022 2y agoIf ClownStrike wanted to take down the site they should deploy another buggy update. They will take the site down along with the rest of the Internet…
- not2b 2y agoOnly those sites that continue to allow every CrowdStrike update to go instantly to every device without any sanity testing would be hit by the next one. Competent IT departments will recognize that they can't risk their business in this way any more. Airlines in particular will have to recognize that they can't afford the hundreds of millions of dollars in losses that could come from a repeat of this, from either CrowdStrike or Microsoft, and come up with a way to update only test systems first.
- para_parolu 2y agoThey didn’t consider first time. Why would they change mind? I believe most companies will still run security theater with crowdstrike or whatever other provider
- hajkflk 2y agoWhat would they do if CrowdStrike were the first search result for "miserable failure"? https://en.wikipedia.org/wiki/Google_bombing#Other_search_engines https://en.wikipedia.org/wiki/Google_bombing#Other_search_en...
- lijok 2y agoDid they try offering clownstrike a $10 uber eats gift card for them to take it down?
- rsingel 2y agoCloudflare's lawyers should have told Crowd strike to kick rocks. The DMCA's copyright provisions apply only to copyrighted content not trademarks. Cloudflare could have told these clowns to go kick rocks without incurring any liability and could have threatened them with filing fake DMCA claims.
- Terretta 2y ago> Cloudflare's lawyers should have told Crowd strike to kick rocks. Not all ISPs use provisions in the DMCA that let them put the burden back on the claimant. A few do. In general, if ISPs or CDNs have a free plan, they can't, as bad actors leverage these free plans in bulk. But ISPs or CDNs that charge actual money to known customers will generally not take down until all legal avenues to keep their client online are exhausted or someone upstream from them blinks which threatens the rest of their customers. It's not a question of getting what you pay for so much as being sure that everyone using the same provider is paying, and having a discussion with the provider before it happens instead of during. You also need all links to play it this way, or you have to host in a different jurisdiction, which may not be possible for some data/content. There are ISPs, CDNs, DNS registrars, data center facilities, backbone providers, who don't take down before asking questions, so if you need to be in the USA, find those. // I have been both a provider refusing to take a client down for nonsense, and a client of those upstream who refused to take us down when our clients were under threat. And yes, when this would happen we spent money rather than cave if the mega corp insisted to go to court, yes the mega corps lost (typically instantly), and yes we donated to EFF.
- Terretta 2y agoMcSherry told Ars that major service providers like Cloudflare can become "chokepoints," where lawful speech gets taken down because, regardless of intent, "they can't be precise in what they do" once their platform gets too big and reports get too numerous. She agreed with Senk that a few large companies controlling vast amounts of content online can be problematic. "It is true that there are a relatively small number of companies that have outsized influence over what is available online," McSherry said. "And that can be really difficult or create a real problem because sometimes they don't have any choice but to sort of overcensor." "In this case, "there was just big companies using big processes and not being careful," McSherry said. "And that is not acceptable." https://arstechnica.com/tech-policy/2024/08/parody-site-clownstrike-refused-to-bow-to-crowdstrikes-bogus-dmca-takedown/ https://arstechnica.com/tech-policy/2024/08/parody-site-clow...
- karaterobot 2y agoI'd have guessed the legal team would have better ways to spend its time right now than pursuing action against an obvious parody. So, this seems like it could be an empty threat to me. But if they intend to proceed, they'd better hurry before Crowdstrike itself collapses under the weight of the lawsuits against it.
- system2 2y ago"CrowdStrike, Inc., CC BY-SA 4.0 https://creativecommons.org/licenses/by-sa/4.0 https://creativecommons.org/licenses/by-sa/4.0, via Wikimedia Commons. License for this derivative work is also under CC BY-SA 4.0 "
- yannk 2y agoI doubt clownstrike.lol is a legit website: I didn't get asked if I wanted to accept cookies.
- nicce 2y agoYou just found a website that does not collect more data than it needs to function.
- jml7c5 2y agoFor reference, this is the site as it appeared when it garnered the DMCA notice: https://web.archive.org/web/20240727134616/https://clownstrike.lol/ https://web.archive.org/web/20240727134616/https://clownstri...
- latentsea 2y agoEasiest way to take down the site is just install crowdstrike on it.
- tamimio 2y agoWhere’s the infringement when the name doesn’t even match?! “Crowdstrike” vs “Clownstrike”? Or is it illegal now to rhyme words? After what happened, that company should be dismantled for good.
- arp242 2y ago> is it illegal now to rhyme words Trademarks have always applied anything that could reasonably be confused with it. So yes, it is illegal to rhyme trademarks. But trademarks has also long since allowed for parody and other usage that doesn't harm the trademark owner. That's why it's a nonsense request, not because of the rhyming.
- tamimio 2y ago> So yes, it is illegal to rhyme trademarks. Do you have any real life examples of that?
- deleted 2y ago[deleted]
- arp242 2y agoDo you also want me to prove the sky is blue and that sex causes babies? It's trademark basics that it applies to anything that can reasonably be confused with it. But please, try starting up Goodle Search or Matflix Streaming and let us know how that went for you.
- Xen9 2y agoI believe this is a reasonable reply. I also believe it's strange you get downvoted!
- tamimio 2y agoI don’t know why you are getting defensive. I asked a clear question on something that I have little knowledge about, and it seemed you do, so it’s a good chance for you to provide more information or details about the topic. Not everyone here is a trademark lawyer. That being said, I did a quick search on both “goodle” and “matflix” and I didn’t find any trademark wars or articles about them. However, I did find fully functional sites with these names.
- Proziam 2y agoAfter all the security events, including the most recent. And after learning they didn't even deploy basic techniques like canary builds to prevent these events. And now this. The pattern seems to reveal that CS truly has no concept of risk management whatsoever. In finance this level of recklessness would get you banned from the industry.
- ffhhj 2y agoSurprisingly clownstrike.com redirects to the parodied site. They are ready for the worst, ironically.
- facorreia 2y agoTo be fair, it's easy to confuse clownstrike.lol with clownstrike.com.
- janmo 2y agoI am familiar with CSC, and have received a multitude of fake DMCA takedown requests from them.They make it look like a DMCA but logos are usually trademarks (TM) and not copyright protected (c). So you cannot send a DMCA. Basically their strategy is to flood the internet with fake DMCA, targeting everything that isn't seen as positive for the brand. I 100% ignore their requests, and so far nothing has happened, keep in mind they send millions of it.
- jimt1234 2y agoDoes anyone have experience with these trademark/DMCA takedown requests? I'm curious, do receivers of these requests really do any sort of due diligence on the requests? Or, do they just rubber-stamp them, and pass them onto the targets of the requests? For example, if I hit YouTube/Google with a trademark/DMCA takedown request, claiming to own the name, "Mr. Beast", and I provide some phoney registration number, they're not gonna act it on...are they?
- cynicalsecurity 2y agoThose clowns from CrowdStrike are digging themselves even deeper, aren't they. What a circus.
- damonlrr 2y agoHow did this go from #1 down to like 20 so quickly? hmmm.... conspiracy
- thewileyone 2y agoDon't call it ClownStrike ... call it ClownsTrike :)
- stuckkeys 2y agoHaha this is pretty funny. Cloud strike should worry about loosing the driver certification instead of chasing after parody sites.
- hcfman 2y agoI thought that parody was a legally protected concept ?
- account42 2y agoWhy is Buttflare even honoring a "DMCA takedown request" for trademark infringement?
- b3ing 2y agoIsn’t this allowed as a Parody? Or do they need to state it up front like first thing on the page