5 ms·
Crowdstrike deserved to go bankrupt for this nonsense, they weren't testing properly, and they rolled their crap update out to the whole world without a staged
by codeulike 1y ago
Crowdstrike deserved to go bankrupt for this nonsense, they weren't testing properly, and they rolled their crap update out to the whole world without a staged rollout or canary system: https://x.com/cyb3rops/status/1821096079372251203 https://x.com/cyb3rops/status/1821096079372251203
Just googled their share price and they are 34% higher than they were before the shitstorm they caused.
- mslansn 1y agoIf all software engineering businesses and engineers that do not test properly went bankrupt then this website wouldn't exist.
- codeulike 1y agoOh come on, we all know and expect bugs, but this was something spectacularly bad. They caused the very thing people were paying them to try and defend from. This incident had very real and serious consequences. https://en.wikipedia.org/wiki/2024_CrowdStrike-related_IT_outages https://en.wikipedia.org/wiki/2024_CrowdStrike-related_IT_ou...
- mslansn 1y agoSo let the market sort it out. Turns out their clients don’t think the consequences were that serious.
- perching_aix 1y agoThey didn't really argue otherwise, just remarked that they think it was. What's your point?
- mslansn 1y agoMy point is that the first post says that Crowdstrike deserved to go bankrupt, but that is up to their clients to decide. Standards for software are very low, and we all profit from that, so better not rock the boat.
- codeulike 1y agoOk that is an interesting point. But my concern with crowdstrike is that the standard seems so very low (imagine the sort of mishaps Mr Bean might have if he moved into the cybersecurity field and you're not far off) that something other than the quality of the software must be driving things. Compliance tickboxing perhaps?
- codeulike 1y agoTurns out their clients don’t think the consequences were that serious. Yeah, thats an interesting point. I'd be interested to read analysis on that. Maybe being seen to pay for something that claims to make things more secure is more important than actually being more secure.
- throwaway290 1y agoThey want compliance not security. Maybe if it's enough for compliance but not enough really then whoever makes compliance standards should be fired
- ourmandave 1y agoDelta Airlines thinks its serious. https://www.theregister.com/2025/05/07/delta_crowdstrike_class_action/ https://www.theregister.com/2025/05/07/delta_crowdstrike_cla...
- jahsome 1y agoThe lawsuit appears to be about the lack of refunds, and even mentions Delta explicitly declined help from Microsoft and CrowdStrike. So how does that indicate Delta thinks "it's" serious? And what is "it"?
- ourmandave 1y agoMore like let the market litigate it out.
- tempfile 1y agoand that would be a bad thing?
- hypercube33 1y agoJust like other security software that's big right now, I'm sure the news that it took down most of the IT systems on earth was great news to shareholders that the software had solid market penetration and most of all that even perhaps one of the biggest outages didn't cause people to leave. The same with Zscaler - people about as far from tech I'm friends with complain to me about how much they hate it so you know /it's everywhere/
- pjmlp 1y agoNot only them, unfortunely proper liability is yet to become as regular as in other industries.
- immibis 1y agoYou have to, because attackers aren't using canary systems. What good is it, if someone finds a new unauthenticated RCE in Windows, and you have to wait a week to make sure your detection method works correctly? By the time the week is over, every computer in the world already has the virus. And then you have to wait another week to test your removal tool.
- codeulike 1y agoNo, you don't have to. Crowdstrikes own documents say they should do a staged roll out rather than all-at-once