Honestly, if we could get that one basic message out, that if their IT security is based on more complexity, not less, that they're doing it wrong, maybe we could start putting crap companies like crowdstrike or citrix out of business.
Top-level
Honestly, if we could get that one basic message out, that if their IT security is based on more complexity, not less, that they're doing it wrong, maybe we could start putting crap companies like crowdstrike or citrix out of business. 23 comments
Actually, the value of Citrix rose after that: https://www.marketscreener.com/quote/stock/CITRIX-SYSTEMS-INC-4863/ These things have no consequences for these companies, it's a completely broken market. I'm reading news that crowdstrike's value dropped, I have doubts that this will be permanent. @HugeGameArtGD @szbalint @hanno it's still caused by a third party software. Had they broken their Linux updater instead of the Windows one, we would get kernel error screens. @Ash_Crow @szbalint @hanno @Ash_Crow @HugeGameArtGD @szbalint @hanno Serious question: Why is #cloudstrike deployed almost everywhere with windows? Is it pushed by MS? Or recommended? Or packaged with MS products? @MarvinFreeman @Ash_Crow @HugeGameArtGD @szbalint @hanno It’s not packaged with or pushed by MS; it’s just the best EDR. @horse @MarvinFreeman @HugeGameArtGD @szbalint @hanno It's also not deployed everywhere. It seems like it is used by "nearly 60% of Fortune 500 companies and more than half of the Fortune 1,000 ", per https://en.wikipedia.org/wiki/2024_CrowdStrike_incident#Impact @hanno Thousands of investors have now heard of CrowdStrike who had never heard of it before, and the stock is at 20% discount! @hanno shows dumb money that doesn't understand what they do how widely used their product is. @hanno Having worked in tech for 30 years and for multiple security companies, I 100% agree. Google is the only one I've worked for that comes close to being the exception, and I think it's just because their security expertise is hard won in keeping *themselves* secure. @hanno For one... I have a ton of Dell thin clients that... just do Citrix connections and nothing else. That's their factory design. You can't just stop when it means deleting a bunch of computer terminals too. @hanno I‘m torn on this one: @hanno it is really interesting how many people including engineers are thinking that a blackbox full of magic promises will do „security“ things for you. |
I'm mentioning citrix specifically because it really boggles my mind how they can be still in business. In case you don't remember, there were countless gov entities, hospitals, and what not, hacked in 2020, due to a really epic fuckup by citrix. It was a flaw they knew about, and hadn't provided a fix, only an unreliable workaround that sometimes didn't work.