7 ms·
Honest question, what should they do? Uninstall the company and give up? Ignoring their actual response, what is a good response to this?
by bitexploder 2y ago
Honest question, what should they do? Uninstall the company and give up? Ignoring their actual response, what is a good response to this?
- gleenn 2y agoIf my company causes billions in damages and endangers human lives, I can't imagine why my company isn't bankrupted and dissolved.
- IAmGraydon 2y agoOk, but the market makes that decision, not the company. Crowdstrike has no choice but to accept the sentence the market hands it. It’s just that the market appears to have sentenced it to…barely anything. Blame those still using CrowdStrike after this incident.
- xenocratus 2y agoIf your company causes damage at society-scale (hell, even if it does major damage to one person's life), the state should be ready to intervene and make the company pay the tab for the damage they caused? Like, that doesn't sound very controversial.
- sb8244 2y agoYea. Their contracts likely have clauses for all of that. I say likely, but we already know this is true because it's come out. The thing is, crowdstrike isn't the only incompetent party here. Many major companies (looking at Delta) probably made it worse for themselves with a very poor response after. So should crowdstrike pay beyond a reasonable measure because of Delta's poor response?
- eftychis 2y agoNo contract clause can protect you from a gross negligence tort. (Or equivalent in one's respective civil law system.) This might be the easiest gross negligence tort case to show and litigate-- still hard but if everyone starts the lawsuits they can not pull the contract to protect them. They will try of course and they will fail in most but the obvious cases. What you can not sue them for is not forseeable damages -- e.g. I lost my dream job because the computer died during the interview. But ceasing operations of a company is generally fair game. And plaintiffs can argue that no reasonable person could forsee and mitigate against this disaster so the failure is not due to plaintiff's "fault" negligence.
- tiahura 2y agoReckless typically requires conscious disregard of risk. Arguably, that would require Crowdstrike emails from programmers saying “this is risky, we need to test it” and management responding “F it! We’ll do it live!” If nobody in CS realized how dangerous their process was, it’s not reckless.
- gleenn 2y agoThat's interesting but my sniff test isn't passing. "Reckless driving" doesn't require me to know it's a bad idea to do 100 miles per hour in a 25, it is reckless whether I realize it or not right? IANAL but the only thing I can think of requiring knowing to be at fault is slander, at least in the USA.
- akira2501 2y ago> Blame those still using CrowdStrike after this incident. I think you'd have to ask "why are they still required to use CrowdStrike or any AV provider?" I think once you find the answers to these questions you realize this is not a properly functioning product market. How you can then build a publicly traded company on the back of a complete and total lie is another subject, but it's certainly also implicated in the above questions.
- lesam 2y agoActually generally the legal system would decide that, not “the market”. I.e. investors have assigned roughly zero probability to CrowdStrike bearing the full cost of this incident, and set the market price accordingly.
- Timber-6539 2y agoThe market as a tool for punishing bad players is far from perfect. It's why we still have monopolies and see consumer antitrusts and other similar legal suits in court. Advocating for shifting blame to customers still using Crowdstrike is ignorant of the problem and further signals a dishonest approach to the issue at hand.
- bitexploder 2y agoEquifax, for example. They probably caused way more damage leaking all our info
- andy81 2y agoThe company should be fined so heavily that they become a goverment asset. With current shareholders wiped out entirely, it should then be re-listed.
- amluto 2y agoIMO the company that this should have happened to is PG&E. I think California could have forced them into liquidation and bought their assets. No bailout required, complete loss for shareholders, and CA could potentially have fixed much of its disastrous utility situation at a reasonable price. A company-ending fine or judgment against Crowdstrike wouldn’t come with any great reason for a public takeover — Crowdstrike could cease to exist and the overall ecosystem would be fine.
- hansvm 2y agoOutside of Alaska and Wyoming, Silicon Valley has the worst power and internet of anywhere I've ever lived (worse than AR, MN, and ND by a longshot), measured either in incremental cost or uptime/availability. The fact that PGE keeps requesting additional rate increases "for fire safety" and immediately kicks those back to shareholders isn't a great look either.
- wiseowise 2y agoHide themselves from the face of the world for at least 5 years until people somewhat forget about them.