CrowdStrike offers a $10 apology gift card to say sorry for outage
techcrunch.com
techcrunch.com
Kitboga is a well-known streamer whose entire schtick is wasting scammers' time. He uses a voice changer and has a very thorough setup of fake websites including Google, the Google Play store, a bank, and more, as well as fake screen sharing tricks that show him exactly what a scammer is trying to do when they use a remote-access tool to access his system. When they use their RAT to black out his screen so they can hide DOM manipulation in the browser or something, he can actually watch them do it.
In the video above, at about 53:00 in, Kitboga "redeems" the fake Google Play Store card that he "bought" rather than letting the scammer copy the numbers.
One thing he's shown many times is how persistent scammers can be. One time he hit the password reset on his fake bank and made the scammer help him solve a password game. https://youtu.be/wkLPk2tmyNI
Actually that'd be far better than if it were really Crowdstrike thinking $10 would resolve this.
So I believe OP cleverly circled that back around to the gift card. WP.
Just like they didn't plan for their testing infrastructure to have its infamous error.
While I do understand that this might have been sent by a department far removed from IT, it's still scary that they didn't think of possible abuse.
More like..."We recognize that we have a moral, ethical, and likely legal obligation to make things right and pay back the damage we have caused...but we're not going to."
The only way I can imagine one-upping the detractors at this point.
Corporate sent us a $25 gift card. Not for each of us, one $25 gift card for a team of 8 people. We had made well over three million in sales that year. Felt like a slap in the face for a job well done.
The $20 is "due consideration" - just like how some deals involve selling an item for a dollar.
Any contract requires consideration. Without it, it's not a valid contract. It doesn't require fair consideration, so a clause giving e.g. $1 is typical for many contracts. They were nice and bumped it up to $20.
I suspect your work DID belong to the company already, under work-for-hire doctrine, but an explicit contract avoids that ambiguity. Ambiguity can be bad and super-expensive, whether during litigation or even something like an audit. If someone is buying a company, investing, making a major loan, that's the kind thing which comes up in due diligence and can be annoying.
So I don't think they were paying you for the code, so much as trying to come into compliance. Very likely, this was triggered by some similar audit for some deal they were trying to make.
> Ambiguity can be bad and super-expensive
If the corporation had some ambiguity in their favor, I expect they would call it "value" and ask for as much as they could get to remove it. But if the ambiguity is in favor of an employee or client, let's remove it for a token $20. Ugly society this one is.
I'm with you, companies will always look out for their own interests, but when clarification minimizes logistical waste, it's possible to benefit everyone.
1) Spend $100k in litigation to discover your boss owns the code
2) Get $20
Fights don't benefit anyone. Some companies would act like dicks and "ask for as much as they could get to remove it," but in most cases, that's not what happens either. A company like that would never get repeat business. Coincidentally, some employees do the same, with similar consequences. And there are employers everyone knows not to work for.
Resolving this sort of thing for a buck -- in the way a court would rule -- is really standard common-sense practice.
We did not get any consideration, cash, or gift cards. Instead we were told that if we didn't sign the new company's mandatory agreements, our employment status could be up for review.
Anytime you see stories of "[insert name of rich CEO or politician] takes salary of only $1", that's why. They can't work literally for free, or the rest of the contract becomes nonbinding.
I am not a lawyer and I don't understand this phrase. But many legal systems require that a contract is at arm's length.
So I would, as part of the contract, hand over $1 or $20 to establish that I have skin in the game and have paid for this contract be valid. The consideration could be stock and other things, but it can’t be null.
As a counter example: In many jurisdictions, a work contract that specifically request lots of overtime or forbids working for a competitor in the future would require a significant extra payment and not 1 USD. 1 USD would not be considered at arm's length.
* Contract law does not require arm's length. A contract for $1 is okay.
* Tax law may require arms length.
* I've never heard of arm's length in employment law, but there are laws which lead to what you describe (e.g. mandatory overtime pay, minimum wage, etc.). In some jurisdictions, there are limitations on how much an employer can change the terms of employment. If you hire me for $100k, and after I quit my old job a week into the new one, you give a pay cut to $80k and otherwise change the terms of the deal, that might not be okay.
The idea in systems which have this rule is that contracts are exchanges of promises and there must be an exchange in order to be valid.
Last time I looked work-for-hire law only takes effect if there is explicit mention of the term "work-for-hire" in the contract, otherwise it's not "work-for-hire". And I have never seen a contract actually mention "work-for-hire".
Do current employment contracts state "work-for-hire"?
So that a conventional employee is covered, but a contractor / consultant with a separate business probably isn't.
https://www.nolo.com/legal-encyclopedia/consideration-every-...
Any contract request that includes a small cash payout should merit extra scrutiny.
We met with their CEO+CFO+lawyers and our lawyers. They were adamant they wouldn't pay the last payment. We pulled out our contract and showed they didn't own any of their code because there was no IP transfer in there. They said "We need a minute." We left the room, came back in and there was a check for the outstanding balance in the middle of the table.
[0] https://hotair.com/jazz-shaw/2018/06/01/jury-awards-family-f...
https://www.tcpalm.com/story/news/local/st-lucie-county/2022...
All involved very split juries - so I think the low amount was kind of a compromise by the jury in each case.
> jurors sent a note to U.S. District Judge Aileen Cannon stating “we are deadlocked. We are unable to come to a unanimous decision.”
> Cannon encouraged them to continue deliberating.
Not in civil trials.
Louisiana and Oregon didn't require unanimous juries in many criminal trials either until 2019 and 2020 respectively.
[1]: https://apnews.com/article/a4f065037299491913827b7d8eda9023
[2]: https://www.findlaw.com/litigation/filing-a-lawsuit/trial-an...
I find it funny that their name, CrowdStrike, sounds like an anti-personnel reaper drone. Now metaphorically fits.
This tone deaf offer just reinforces the impression that they are just a bunch of clowns.
Probably bullshit, but honestly... Wtf is up with the name?
Maybe it's controlled by the CIA, or maybe just has a quiet contract with USCYBERCOM and/or ARCCYBER.
I mean, people don't seem that concerned about all of the nuclear missiles and submarines, aircraft carriers, and US military bases everywhere. Computers and the internet are now part of that and have been for quite awhile. If you are invested in this system then you probably want that dominance to continue (otherwise you should probably start learning Chinese). In which case we probably need something like a "crowd strike" widely deployed on the monopoly OS so that we have offensive capabilities.
If you don't like that idea then why use Windows at all? Use Linux at least.
I don't think this is really conspiracy theory territory unless you are in denial that cyberwarfare exists or that the US must participate in it.
...wait
At least an Amazon gift card is near its cash value, when you account for the markup on food delivery that $10 is about 4 USD
(Also, people who want McDonalds 20 minutes after it was remotely edible and shaken to shit on the back of a moped, who are you? I see the bikes everywhere but have never met one of you irl)
What an awful coincidence. I can’t even imagine how it must feel to have a freak technical accident deprive you of seeing your father for the last time.
Anything could have caused that really. Still very unfortunate but c'est la vie sometimes.
Ouch. That has potential to go that bit extra badly in the press/media too.
Though with the scale of ClownStrike's fuck up, they might not even notice.
At no point did anyone think "this doesn't seem like the right response, I should warn someone further up the chain". Probably due to the idea coming from further up the chain.
And those ubereats/doordash/grubhub cards are worthless because $10 won't get you a thing, you'll need to spend another $30. Which is why corporate always buys those because I am guessing they're much less than $10 to buy.
What an utter clown strike.
I just don't immediately believe a publicly-traded company with this many users does something this stupid.
In that case, BP basically threw away their consumer brand in the US - they turned every single BP station into an Arco station (their subsidiary, "lower quality" brand at the time). Then they sold off or spun down a huge portion of their businesses to set aside money for legal fees.
I don't know if Crowdstrike really has any other options at this point. The amount of legal liability the company is going to be under will be staggering and the brand reputation is worse than worthless.
That must not have lasted long. I don't recall a time when there wasn't a BP station during and after that disaster.
ARCO is apparently a gas station brand owned by Marathon but also resells BP in a few west coast states.
Amoco, ARCO… naming things is hard I guess even outside computer science.
Citation for legal liability Crowdstrike has?
Re reputation - I've read this about all sorts of annoyances that had real economic impact, i doubt this will make crowdstrike worthless any more than:
* MS became worthless after Code Red or Slammer or any of the other late 90s/early 2000s breaches.
* Apple became worthless after the iPhone that requried you to hold it a certain way while talking
* Toyota became wortheless after the unintended acceleration issues
* Facebook became worthless after screwing up the internet for a day.
* Amazon become worthless after US-EAST went down screwing everyone over for an afternoon (pick a time).
* Norfolk Southern became worthless after the east palastine derailment.
* A thousand others....
This issue wasn't as impacting as many of those - some computers were down for a few hours and it made a mess. It takes a lot more than that to destroy a company or their brand reputation. Look how many people choose comcast- even in areas where there is good competition with fiber from a local reputable ISP.
Look at other security related companies of similar age and entrenchedness...
Okta was breached twice by bad auth on their ticketing system. They are an auth company. This led to other hacks. They still are doing OK, with growing revenue.
Solarwinds was breached and became the attack vector for several major hacks. They are still doing OK - in fact revenue has grown since then. (although solarwinds is much older).
Cloudflare has caused major outages - their revenue has grown too.
And on and on.
Crowdstrike has had a rough 2024. They are also still the company that was called in to consult on breach after breach for the last decade+. If they get their shit together, next month at defcon Crowdstrike people will likely be drinking for free (and being the butt of some jokes). By next year few people will even remember this, and very very few will be uspet/angry about it. A huge number of affected IT people are already looking at it as "haha those guys messed up" and not even thinking about "how do we get off crowdstrike". No software is perfect, and very little of it is even any-good - people are willing to give those who make generally decent software (and have an otherwise good reputation) a lot of slack.
I could be wrong, but I really doubt this kills the company or the brand rep.
Which was based on cold calling people who in general did not need them and telling them they did.
(I was young and innocent at the time, and I didn't figure this out right away) (I had not even seen boilerroom)
I worked in IT. We created a fantastic tool (it really was) that managed the entire process.
You could put someone in front of a screen, given them a phone and the software would guide them.
1. Name, address, number to call. 2. Script for selling, whith branches depending on how the conversations was going. Obviously we could only cover small subsets of possible paths. (but it was reasonably good, since the conversations tended to be much the same)
Let us say the conversation went well. In order to make the sale, a number of government and financial forms had to be filled out,
3. Highly guided and simplified data entry that would at the end of the process cause all forms and documents to be issued.
4. As part of the process prompts for specific things the customer had to be told to be in compliance
5. Documents go out by Fedex.
(then some boring stuff)
The concept was that you could take someone off the street, who had no training or understanding of the product or financial matters etc etc, put a phone in front of then start the software and bang.
The reason I have bored you dear reader with all of that is coming up.
At Christmas bonuses were paid out. People in sales got some huge $$$$$ cash bonuses and there were some expensive gifts in there as well. Including a horse,.
Makes sense.
The IT department... We got coupons for 50% off at Heavenly Ham. (or something like that).
We were not amused.
Crowdstrike is sending what? Like 15 $10 cards to the little area in IT that handles desktops/kiosks/atms/etc? Or the to the Cyber area that bought it, but mostly wasn't saddled with fixing the issue?
Specifically, “partners” were getting gift cards and there is no mention of customers. It sounds more like they were throwing around gift cards to channel partners, MSP’s, contractors, etc. It’s still tone deaf but a far cry from a $10 apology to customers.
This is a[nother] highly unserious move and unforced error.
Instead, let me offer the following, alternative snark: "If I were to share with you the secret of renaming your C-*.sys files to C-*.tmp prior to trying to ingest them, so that if you crash while doing so, you will not repeat that mistake right after rebooting, how many US$10 gift cards is that worth? Keeping in mind, of course, that is, like, 2 hours of parking where I live?"
As if a $10 gift card is anywhere near compensating enough for people impacted by their incompetence. Some people were impacted by delayed flights. Some people were impacted by degraded medical care.
I wonder how much money in total they represent, and if CrowdStrike would have come out better saying "We've immediately allocated $X amount of funds to making sure this issue won't happen again" instead of dividing in x * $10 uber eats insults.
I would what cold hard cash, plus I do not want to put a sypware app on my phone for just $10.
I can see someone thinking $10 was a nice idea, but letting the impact settle a bit before narrative reingagement would have seemed wiser. Interesting to think about what to do instead though. Thought of discounts on renewals or account credits, but anything that seems like bargaining is going to get flak. In terms of who was really affected by the outages, maybe demonstrate recognition by donating to a PTSD or family support charity. wonder what thinking of each customer is a person in a family would do to tech product decisions in general.
The Management class is so far removed from reality they can't even see when they accidentally write their own satire.
First thing you do in a crisis? Take a few breaths and calm down. Take the pressure off of yourself. Agree to a timeline and start gathering ideas. Brainstorm. Engage in risk assessment. Then decide, act, and re-evaluate.
Other examples include memories of the respective title component of the Berenstain Bears children's books being spelled "Berenstein", the logo of clothing brand Fruit of the Loom featuring a cornucopia, Darth Vader telling Luke Skywalker, "Luke, I am your father" in the climax of The Empire Strikes Back (he actually says, "No, I am your father" in response to Skywalker's assertion that Vader killed his father), Mr. Monopoly wearing a monocle, and the existence of a 1990s movie titled Shazaam starring comedian Sinbad as a genie.
e.g. https://fortune.com/2024/07/19/cloudstrike-microsoft-massive... https://www.standard.net/news/business/2024/jul/23/lessons-l...
Looks like a minority, though it's concerning that Fortune reported it with an incorrect name.
Our company has already paid a lawyer to get our lost money back
They're trying to use the equivalent of "pizzas for everyone who works late for this crunch!", and consider the matter closed.
That's really not going to work.
So cool much appreciated CS ~~ good lookin out ! I even beat my coworker to the code he was so mad lol
Now $10 on Uber Eats? Hope I can redeem that code before one of you losers does… Last one there is a rotten egg!
So randooom heheh aww we like to have fun . My boss is so mad that we had no production for 20 hours, but stuff happens what can you do D;