7 ms·
Reputational damage from this is going to be catastrophic. Even if that’s the limit of their liability it’s hard not to see customers leaving en masse.
by agrajag 2y ago
Reputational damage from this is going to be catastrophic. Even if that’s the limit of their liability it’s hard not to see customers leaving en masse.
- dandanua 2y agoThe company will perish, there is no doubt in that.
- icelancer 2y agoExtremely unlikely. This isn't the first blowup Crowdstrike has had; though it's the worst (IIRC), Crowdstrike is "too big to fail" with tons of enterprise customers who have insane switching costs, even after this nonsense. Unfortunately for all of us, Crowdstrike will be around for awhile.
- zik 2y agoBusinesses would be crazy to continue with Crowdstrike after this. It's going to cause billions in losses to a huge number of companies. If I was a risk assessment officer at a large company I'd be speed dialling every alternative right now.
- ajscanlan 2y agoit would be crazy not to at least investigate migration paths away from Crowdstrike, or better redundancies for yourself
- hello_moto 2y agoCybersecurity industry has regular and annual security testing/competitions done by various Organizations that simulates tons of attacks. Vendors are tested against these cases and graded with their effectiveness. I heard Crowdstrike is "best-in-market" for good reasons as others who have more deep knowledge of the industry have shared in this thread.
- zik 2y ago> I heard Crowdstrike is "best-in-market" A friend of mine who used to work for Crowdstrike tells me they're a hot mess internally and it's amazing they haven't had worse problems than this already.
- hello_moto 2y agoThat sounds like any other companies I have ever worked for: looks great from the outside but a hot mess on the inside. I have never worked for a company where everything is smooth sailing. What I noticed is that the smaller the company, the less hot mess they are but at the same time they're also struggling to pay the bill because they don't innovate fast.
- esskay 2y agoNah they'll be fine. It happened 7 months ago on a smaller scale, people forgot about that pretty quickly. You don't ditch the product over something like this as the alternative is mass hacking.
- daemin 2y agoAs someone said earlier in these comments the software is required if you want to operate with government entities. So until that requirement changes it is not going anywhere and continues to print money for the company.
- bdd8f1df777b 2y agoSurely there are more than one anti-virus that can check the audit box?
- daemin 2y agoFrom experiencing different AV products at various jobs, they all use kernel level code to do their thing, so any one of them can have this situation happen.
- camdenreslink 2y agoPresumably those other companies try running things at least once before pushing it to the entire world though.
- daemin 2y agoI'd kind of expect IT administrators to try out these updates on a staging machine before fully deploying to all critical systems. But here we are.
- linksnapzz 2y agoYou, the admin, don't get to see what Falcon is doing before it does it. Your security ppl. have a dashboard that might show them alerts from selected systems if they've configured it, but Crowdstrike central can send commands to agents without any approval whatsoever. We had a general login/build host at my site that users began having terrible problems using. Configure/compile stuff was breaking all the time. We thought...corrupted source downloads, bad compiler version, faulty RAM...finally, we started running repeated test builds. Guy from our security org then calls us. He says: "Crowdstrike thinks someone has gotten onto linux host <host>, and has been trying to setup exploits for it and other machines on the network; it's been killing off the suspicious processes but they keep coming back..." We had to explain to our security that it was a machine where people were expected to be building software, and that perhaps they could explain this to CS. "No problem; they'll put in an exception for that particular use. Just let us know if you might running anything else unusual that might trigger CS." TL;DR-please submit a formal whitelist request for every single executable on your linux box so that our corporate-mandate spyware doesn't break everyone's workflow with no warning.
- alch- 2y agoI mean, Boeing is still around...
- tcmart14 2y agoWhile it probably should, I regret to inform you that SolarWinds is still alive and well.
- junto 2y agoIronically some /r/wallstreetbets poster put out an ill-informed “due diligence” post 11 hours ago concerning CrowdStrike being not worth $83 billion and placing puts on the stock. Everybody took the piss out of them for the post. Now they are quite likely to become very rich. https://www.reddit.com/r/wallstreetbets/s/jJ6xHewXXp https://www.reddit.com/r/wallstreetbets/s/jJ6xHewXXp
- BoringTimesGang 2y agoA convenient alibi?
- RateMyPE 2y agoThat user is the equivalent of using a screwdriver to look for gold and succeeding.
- persedes 2y agoWhat's even better is the reaction here: https://www.reddit.com/r/sysadmin/comments/1e6vx6n/comment/ldw0fgf/ https://www.reddit.com/r/sysadmin/comments/1e6vx6n/comment/l...
- deliveryboyman 2y agoNot sure what material in their post is ill-informed. Looks like what happened today is exactly what that poster warned of in one of their bullet points.
- rozap 2y agoYea, everyone is dunking on OP here. But they essentially said that crowdstrike's customers were all vulnerable to something like this. And we saw a similar thing play out only a few years ago with SolarWinds. It's not surprising that this happened. Ofc with making money the timing is the crucial part which is hard to predict.