this post was submitted on 01 Aug 2024
326 points (99.1% liked)

Technology

59589 readers
3148 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] cbarrick@lemmy.world 46 points 3 months ago (7 children)

[S]hareholders said they learned that CrowdStrike’s assurances about its technology were materially false and misleading when a flawed software update disrupted airlines, banks, hospitals and emergency lines around the world.

I don't see how they can make this argument.

Falcon is a kernel module. When kernel modules fuck up, you get kernel panics.

Sure, the layperson may not know enough about computers to recognize this, but it's a basic enough fact about operating systems that an investor in a company like this should take the time to learn. It's not like they hid that fact.

If you invested in a company without knowing how their product works, that's on you.

[–] thesmokingman@programming.dev 21 points 3 months ago (4 children)

You highlighted the wrong portion of this article.

The complaint cites statements including from a March 5 conference call where Kurtz characterized CrowdStrike’s software as “validated, tested and certified.”

If the CEO is making claims that the software is tested and certified, then the CEO should be able to prove that claim, no matter where the software lives. It is very reasonable to say, at face value, the CrowdStrike testing pipeline was inadequate. There is a remote possibility that there were mitigating factors, eg some other common software update released right before from another vendor that contributed; given CrowdStrike’s assurances and understanding of where it falls in most supply chains I consider that to be bullshit. I personally haven’t seen anything convincing that shows a strong and robust CI pipeline magically releasing this issue.

Now shareholder lawsuits are bullshit in general and, as someone constantly pushed to release without fucking any confidence, I think it’s really fucking dumb to ever believe any software passes any inspection until you have actually looked at the CI/CD process in-depth.

[–] ArgentRaven@lemmy.world 6 points 3 months ago (2 children)

To add to that, I very much doubt any big company tests and verifies anything anymore.

Boeing ships planes with missing bolts and proper software, Crowdstrike pushes updates with no testing, we've all seen Microsoft push updates that break stuff because there's no testing, and that's just what comes to mind.

That's how they maximize profits - get rid of testing environments, do minimal checks, and have the one guy doing 3 jobs at once just push it to production.

I've been in IT for the banking industry for over a decade and I promise you, we're all a missed cup of coffee or a comma away from another massive outage due to a program or network misconfig.

As long as business culture is set to maximize profits for one quarter, I wouldn't trust a sales website about "verification" or "disaster recovery backups" any more than I trust a used car salesman.

That goes for Crowdstrike, but also all of their competitors.

[–] thesmokingman@programming.dev 4 points 3 months ago

I’ve got friends at Boeing on DoD contracts. Not only is it waterfall, it gets tested hardcore. My experience in private industry is the exact opposite. A consultancy I know of just lost (pretty sure) a state contract because they opened shit up to the public because, surprise surprise, they didn’t test their infra changes.

Now I will say that when I have had to manage client SLAs and there is a cost to post-release defects and change requests, testing increases. Not to the level I’m super comfortable with (which is well below perfect, mind you; I like shipping more than once in a lifetime), but a bit more.

load more comments (1 replies)
load more comments (2 replies)
load more comments (4 replies)