5 ms·
> CrowdStrike said Sunday that its liability is contractually capped at an amount in the “single-digit millions.” Companies handling critical infrastructure sh
by latentnumber 2y ago
> CrowdStrike said Sunday that its liability is contractually capped at an amount in the “single-digit millions.”
Companies handling critical infrastructure should face more scrutiny imo.
- crngefest 2y agoBy more „scrutiny“ do you mean increase the liability cap?
- latentnumber 2y agoYes, because that incentivizes such companies to be more diligent.
- chronid 2y agoCrowdstrike is not handling critical infrastructure. Delta is. The reality is the industry wants its cake and eat it too. No one forced Delta to buy a software which could force upgrades in their production fleet. They're a billion dollars company, and should put their big boys pants on.
- willhackett 2y agoAm I right in thinking Delta could have chosen when the update was distributed to its infrastructure? In my mind, a quick test run of the update on a VM before letting it roll out globally would have revealed the BSOD boot loop.
- uncivilized 2y agoNo. The update was forced
- chronid 2y agoAFAIK crowdstrike can push updates at any time at any host. There are staging areas they may use, but don't have to (particularly for definitions updates). Crowdstrike should have done a better job, but Delta chose them (to offload the responsibility and work) and now they're claiming foul. They knew the risk. This is a classic executive play of claiming the fault lies in the consultants/vendor and taking no responsibility.
- wpm 2y agoJust shows how many planes would be falling out of the sky if there weren't federally mandated safety systems, secondary hydraulic circuits, and failover hot spares at nearly every layer of the stack. Delta should've had backup systems, just like their planes do.
- willhackett 2y agoOkay, good to know. I always thought those embedded systems would be a real pain to maintain.
- ijk 2y agoI'm not sure how "you should never use CrowdStrike" is an argument in CrowdStrike's favor. I guess you're saying they shouldn't have outsourced in the first place? Which does sound like the correct conclusion in this case...
- chronid 2y agoI'm not trying to defend CrowdStrike, but pointing to the fact Delta is the one maintaining and owning critical infrastructure and the executives trying to shift this responsibility onto someone else is the reason this happened in the first place. :)
- oglop 2y ago> Crowdstrike is not handling critical infrastructure. lol.
- FireBeyond 2y ago> No one forced Delta to buy a software which could force upgrades in their production fleet. Except this update was one from CrowdStrike that would ignore Delta's stated update policy. And they literally said "Oh, yeah, we can configure some updates to bypass your policy". I wonder how well this was communicated to those customers.
- chronid 2y agoDid crowdstrike force delta to accept running what essentially is a permanent RCE in their production fleet? You do not buy a software that is capable to do that and you put the fact it's not capable of doing that in the contract. The update policy may work for the client version updates, but not for the "policy definition", otherwise delta won't get the sweet "all vulns mitigated with a 4h SLA" they crave.
- amy-petrik-214 2y agoI mean. Delta is also an airline, and if airline's love to do one thing it's to point fingers and shift blame. Mostly such that they don't reimburse you what you are legally owed if they jam you up, but also it seems throughout.
- HarryHirsch 2y agoCompare that to the Colonial Pipeline ransomware hack, where a Russian group disabled critical infrastructure by accident and the Russian government intervened. Crowdstrike on the other hand - national infrastructure is taken out and no word from the agencies on how to prevent a re-run.
- AnimalMuppet 2y ago> CrowdStrike said Sunday that its liability is contractually capped at an amount in the “single-digit millions.” Well, that's nice. If I understand correctly, though, you can't contractually limit liability for gross negligence. I mean, you can say it in the contract, but it isn't legally enforceable. It does raise the bar, though - gross negligence is harder to prove than ordinary negligence. Note well: IANAL. I could be wrong.