I wouldn’t want to live in a world where people can get away with mistakes like this: as far as I have seen, if one person in CS had actually tried this file on their local windows machine, it would’ve crashed. That’s not a small thing is it? That’s a Boeing like culture which should be terminated today.
I accept shared responsibility when there is some agreed deployment and such scenarios, but here? Nope it is on CrowdStrike...
If I give root to a third party, then I’m liable for everything they do with that root.
The correct comparison would be handing your house keys to a licensed insect exterminator and the guy accidentally poisoning your family. You of course are not liable if a professional supplying you with a service messes up.
It’s like paying a licensed insect exterminator that uses random chemicals. They tell you this and you hand over the keys anyways.
I don't consider them capable of preventing something like this from happening again.
I think trading, say, small x (15 minutes, an hour?) time, to stage rather than blast might be an acceptable tradeoff given the visible consequences of not doing so.
Our essential services should be built on a more secure OS, if windows isn’t suitable.
So it sounds like you agree that Crowdstrike should go bankrupt.
> Our essential services should be built on a more secure OS, if windows isn’t suitable
Oh wait you blame Windows for this?
- https://www.crowdstrike.com/blog/crowdstrike-brings-xdr-to-z...
Or maybe not to boot . . .
Because critical infrastructure doesn't get the convenience of shifting the blame. They must account for these risks in advance. Do you know what happens when IT breaks down in a bank? They've got two or more printers that print all new transactions. Database corruption? No problem, we've got the transactions right there. Printer breaks down? No problem, we've got another one printing the transactions right there. Hospitals don't get the luxury of shifting the cause of death from them failing to properly account for risks to a piece of software.
Hypothetically, if there was a widespread 'bug' in... Intel CPUs that caused a similar issue, would you say it was the hospitals that should be held accountable, or Intel, or someone else? What about if the issue was in Windows itself - what should each hospital do differently that would have avoided this?
When the damages are in the billions we need to make sure that there are billions in liability to balance the scales. Or else there will always be a perverse incentives to not give a shit.
Whose incompetence is that? If a hospital pays for an energy redundancy solution where the vendor basically communicates "please don't use us for anything important", and then a power outage costs lives, are we seriously saying that the hospital shouldn't have to pay big time?
I'm not saying that CS shouldn't be liable. I'm saying that when consumers are looking for someone to sue, and regulators are looking for someone to punish, those who directly interface with the consumer should be in the direct line of fire. Hospitals in turn should be able to sue CS.
We certainly should not prefer that the blame goes straight to the engineer as then the consumer would basically have nobody to sue. That's a world of even less accountability. Those who are most capable of taking responsibility should take responsibility, and not merely those who are most blameworthy from first principles of local causality.
There could be billions of dollars of damage here. There must be billions in liability as well to balance the economic scales. This is way past the single individual who pulled the trigger.
This is ridiculous.
None of these business can (or should) handle all of their infosec internally. They must use vendors. And because they don't have infosec expertise, they have no way to verify that a vendor has good quality control.
You're essentially arguing that a hospital should also be responsible if people die because they bought the wrong MRI machine brand or one of their trucking suppliers had a crash and couldn't bring them enough of a certain drug.
There is no universe where vendors shouldn't be responsible for failing to deliver a safety-critical service that they 100% guaranteed they could deliver. There was nothing in the CrowdStrike contract that said, "Updates may inadvertently disable all systems that receive them," because that would mean no one should ever use it.
As a customer you should not have to assume the software your supplier vends is faulty to the extent of this incident.
It's reasonable for a customer to assume the software is tested according to industry best practices.
CS acted grossly negligent here, and they deserve the majority of the blame.
I agree that some blame also resides with customers, there must be disaster recovery procedures in place to allow them to function with minimal downtime in the case of emergency services.
But this incident was so deep, that the SPOF here was using Windows. So now, your DR plan needs to account for some mandatory percentage of your OSs not being Windows, and your IT staff being maybe Linux experts. Cool.
But can you predict that you need to store your bitlocker keys in both platforms? And can you even do that or is it one of those things where bitlocker storage has to be on windows bc of lockin?
Who's gonna rock that boat?
People are now literally invested in in a system that tolerates, if not ofttimes rewards, bad behavior from companies all the way from small things right up to "deliberately poisoning/cooking the whole ecosystem to make a buck"
I am a shareholder in dozens of companies. I have zero oversight on how things are managed. The only thing I can do is sell my paltry amount of shares if I think things are not going well there.
Shareholders would be punished in this case in the sense that crippling fines and reparations that Crowdstrike should definitely be liable to pay would decimate the stock value.
And if criminal charges were to be pressed, then the people actually in charge of the company should be on the hook. For example, if someone dies because CS was horribly negligent in their duties, then that should be a possibility.
and to be fair, having some sort of tool like that isn't necessarily a bad thing, the problem is when the tool gets pushed without testing and breaks the internet.
/s