• A_Porcupine@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    2 months ago

    This is very misleading!

    CrowdStrike did not send gift cards to customers or clients. We did send these to our teammates and partners who have been helping customers through this situation. Uber flagged it as fraud because of high usage rates.

    • SkaveRat@discuss.tchncs.de
      link
      fedilink
      arrow-up
      0
      arrow-down
      1
      ·
      2 months ago

      I mean, it makes it a little better, but I’d still be annoyed by it just being 10 bucks.

      They might as well not do it. I’d be more insulted than a boss throwing a pizza party

  • digdilem@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    I lost a day’s holiday, and our team spent 8 man days on this entirely preventable mistake.

    $10? Try extending our licence by another year for free, that might start going towards it.

    • MrMcGasion@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      2 months ago

      Why would you want another year of their software for free? This is their second screw up (apparently they sent out a bad update that affected some Debian and RHEL machines a couple years ago). I’d be transitioning to a competitor at the first opportunity. It seems they aren’t testing releases before pushing them out to customers, which is about as crazy to me as running alpha software on a production system.

      I’m sure you have reasons, and this isn’t really meant to be directed at you personally, it’s just boggling to me that the IT sector as a whole hasn’t looked at this situation and collectively said “fuck that.”

        • Scrubbles@poptalk.scrubbles.tech
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          Nah, I don’t buy that. When you’re in critical infrastructure like that it’s your job to anticipate things like people being above or below versions. This isn’t the latest version of flappy bird, this is kernel level code that needs to be space station level accurate, that they’re pushing remotely to massive amounts of critical infrastructure.

          I won’t say this was one guy, and I definitely don’t think it was malicious. This is just standard corporate software engineering, where deadlines are pushed to the max and QA is seen as an expense, not an investment. They’re learning the harsh realities of cutting QA processes right now, and I say good. There is zero reason a bit of this magnitude should have gone out. I mean, it was an empty file of zeroes. How did they not have any pipelines to check that file, code in the kernel itself to validate the file, or anyone put eyes on the file before pushing it.

          This is a massive company wide fuckup they had, and it’s going to end up with them reporting to Congress and many, many courts on what happened.

        • digdilem@lemmy.ml
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          Not just Crowdstrike - any vendor that does automatic updates, which is more and more each day. Microsoft too big for a bad actor to do as you describe? Nope. Anything relying on free software? Supply chain vulnerabilities are huge and well documented - its only a matter of time.