{"id":4786,"date":"2024-08-08T16:15:58","date_gmt":"2024-08-08T21:15:58","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/crowdstrike-s-legal-pressures-mount-could-blaze-path-to-software-liability"},"modified":"2024-08-08T16:15:58","modified_gmt":"2024-08-08T21:15:58","slug":"crowdstrikes-legal-pressures-mount-could-blaze-path-to-liability","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/08\/crowdstrikes-legal-pressures-mount-could-blaze-path-to-liability\/","title":{"rendered":"CrowdStrike&#8217;s Legal Pressures Mount, Could Blaze Path to Liability"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltd399556d3a8abf22\/669fd6cd436379475fe4953d\/crowdstrike_T.Schneider_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/crowdstrikes-legal-pressures-mount-could-blaze-path-to-liability.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/crowdstrikes-legal-pressures-mount-could-blaze-path-to-liability.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The CrowdStrike update that hobbled businesses, disrupted consumer travel plans, and took French and British broadcasters offline has predictably led to a host of lawsuits filed by investors and customers of both CrowdStrike and other affected companies.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yet, the incident could lead to another destination: Software liability.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The overall consensus among legal experts is that CrowdStrike is likely protected by <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.crowdstrike.com\/terms-conditions\/\" rel=\"noopener\">its Terms and Conditions<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> from reimbursing customers for more than they paid for the product, limiting its software liability in what the company now refers to as &#8220;the Channel File 291 Incident.&#8221; However, the fact that affected businesses and consumers have little recourse to recover damages will likely lend momentum to legislation and state regulations to hold firms responsible for such chaos, says Chinmayi Sharma, associate professor of law at Fordham University.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This is an extremely interesting and important example of why the call for greater software liability is urgent, from the standpoint of protecting critical infrastructure and protecting the consumer,&#8221; she says. &#8220;There are these massive barriers in existing doctrine that prevent users, licensees, purchasers of software, and third parties from bringing successful lawsuits against software manufacturers, and so I think that this will be an exemplary case of why reform is necessary to address those big barriers.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">On July 19, CrowdStrike pushed an update to its sensors to detect additional attacks that use a particular Windows features known as &#8220;named pipes.&#8221; According to the firm&#8217;s <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.crowdstrike.com\/wp-content\/uploads\/2024\/08\/Channel-File-291-Incident-Root-Cause-Analysis-08.06.2024.pdf\" rel=\"noopener\">August 6 root-cause analysis<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, the update\u2014a Channel File numbered 291\u2014&#8221;defined 21 input parameters, but the integration code &#8230; supplied only 20 input values to match against.&#8221; The difference caused an out-of-bounds memory read, leading the Windows systems that received and applied the update to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/crowdstrike-will-give-customers-control-over-falcon-sensor-content-updates\" rel=\"noopener\">crash with the Blue Screen of Death<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The bad update affected 8.5 million computers, caused at least $5.4 billion in damages to the Fortune 500, and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/companies-struggle-to-recover-from-crowdstrike-crippling-falcon-update\" rel=\"noopener\">caused widespread operational disruption, particularly among airlines and healthcare firms<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/d18rn0p25nwr6d.cloudfront.net\/CIK-0000027904\/073daaf9-c982-4c0a-bec4-841194f94c91.pdf\" rel=\"noopener\">a statement filed with the SEC on August 8<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, Delta\u2014the worst-hit airline\u2014estimated a $380 million direct revenue impact due to its refunding of customers for canceled flights and $170 million in recovery costs. The company canceled 7,000 flights over five days, angering its customers, but also leading to a scant savings of $50 million in fuel due to the cancellations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;An operational disruption of this length and magnitude is unacceptable, and our customers and employees deserve better,&#8221; Ed Bastian, CEO of Delta, said in the filing, adding: &#8220;We are pursuing legal claims against CrowdStrike and Microsoft to recover damages caused by the outage, which total at least $500 million.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Lawsuits Already on Tap\">Lawsuits Already on Tap<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Delta is far from the only lawsuit. CrowdStrike is facing class-action lawsuits from investors after its stock price plummeted more than 36%, from $343 on July 18\u2014the day before the bad update\u2014to less than $218 on August 2.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The incident has resulted in numerous shareholder lawsuits, and not just against CrowdStrike, but against Delta as well. A sampling of current lawsuits:<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The incident has led to an investigation by the US House Committee on Homeland Security.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While investor lawsuits and government investigations will have different goals, customer lawsuits\u2014such as Delta&#8217;s and the potential small-business lawsuit\u2014will have an uphill battle. As CrowdStrike&#8217;s attorneys pointed out in a letter to Delta, business customers would need to explain why liability limits in established contracts should be considered moot, detail every action taken or not taken to recover from the outage, and explain in what ways their infrastructure was designed to be resilient.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Delta\u2019s public threat of litigation distracts from [our recovery] work and has contributed to a misleading narrative that CrowdStrike is responsible for Delta\u2019s IT decisions and response to the outage,&#8221; <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.ciodive.com\/news\/crowdstrike-delta-negligence-claims-lawsuit-letter\/723371\/\" rel=\"noopener\">the company&#8217;s attorney stated in the letter<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. &#8220;Should Delta pursue this path, Delta will have to explain to the public, its shareholders, and ultimately a jury why CrowdStrike took responsibility for its actions\u2014swiftly, transparently, and constructively\u2014while Delta did not.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As for the burgeoning shareholder lawsuits?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We believe the cases lacks merit and we will vigorously defend the company,&#8221; a CrowdStrike spokesperson told <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">Dark Reading<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Software Liability's Long Road\">Software Liability&#8217;s Long Road<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yet, the outage and its legal fallout might only fuel the effort to hold software companies more liable for their products. Currently, the bar is so high for bringing a successful case against a software maker that most attorneys are disincentivized to even try, says Fordham&#8217;s Sharma.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;How these cases go will give us a lot of insight into how high are these barriers, what needs to be reformed,&#8221; she says, adding: &#8220;We don&#8217;t have a lot of case law on this &#8230; so this will be very exemplary in shedding light on exactly what the contours of those barriers are.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The software liability landscape is currently pretty craggy. While simple on its surface\u2014&#8221;software makers must be held responsible for insecure software&#8221;\u2014even the question of who is responsible can quickly become complex, as the interplay between Delta Airlines, CrowdStrike, and Microsoft shows.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Software liability legislation and regulations would have to solve this issue and many others, the Atlantic Council&#8217;s Cyber Statecraft Initiative stated in <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/dfrlab.org\/2024\/01\/16\/design-questions-in-the-software-liability-debate\/\" rel=\"noopener\">a 32-page analysis published earlier this year<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Software security is a problem of &#8216;shared responsibility&#8217;: users of software, in addition to its developers, have significant control over cybersecurity outcomes through their own security practices,&#8221; the report stated. &#8220;Torts already have conceptions of &#8216;comparative negligence&#8217; when the behavior of the harmed party contributed significantly to the harmful outcome\u2014policymakers might want to map this concept explicitly to the software context to balance certain policy goals.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Even if software-liability regulations were established, however, CrowdStrike would likely exceed those requirements, says Brian Fox, CTO of Sonatype, a software integrity company. He pointed out that &#8220;a series of relatively minor mistakes led to an eventual collision when a final factor was dropped into place.&#8221; While some have claimed that the company did not test its updates, it&#8217;s more likely that the company just did not account for all possible scenarios\u2014a common failure, he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We badly need reform to rebalance corporate risk-taking on behalf of their customers, [but] the specifics of how this issue unfolded likely make it only a part of the case study for reform,&#8221; Fox says. &#8220;This is unfortunately very typical in software and highlights why we aren\u2019t ready for perfect strict liability standards.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/crowdstrike-s-legal-pressures-mount-could-blaze-path-to-software-liability\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The CrowdStrike update that hobbled businesses, disrupted consumer travel plans,<\/p>\n","protected":false},"author":12,"featured_media":4787,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4786","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/crowdstrikes-legal-pressures-mount-could-blaze-path-to-liability.jpg?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/crowdstrikes-legal-pressures-mount-could-blaze-path-to-liability.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/crowdstrikes-legal-pressures-mount-could-blaze-path-to-liability.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/crowdstrikes-legal-pressures-mount-could-blaze-path-to-liability.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/crowdstrikes-legal-pressures-mount-could-blaze-path-to-liability.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/crowdstrikes-legal-pressures-mount-could-blaze-path-to-liability.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/crowdstrikes-legal-pressures-mount-could-blaze-path-to-liability.jpg?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/crowdstrikes-legal-pressures-mount-could-blaze-path-to-liability.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/crowdstrikes-legal-pressures-mount-could-blaze-path-to-liability.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/crowdstrikes-legal-pressures-mount-could-blaze-path-to-liability.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/crowdstrikes-legal-pressures-mount-could-blaze-path-to-liability.jpg?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4786","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4786"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4786\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4787"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4786"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4786"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4786"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}