RE: O/t..crowdstrike sp ..could be interesting later..19 Jul 2024 17:44
"It just roll updates out with testing, so while crowd strike are the root cause, the company is culpable"
No doubt the Lawyers are all over this to determine if they can go after Crowdstrike, and see if there's arguments nullifying Crowdstrike's disclaimers.
"Limitation of Liability. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW CROWDSTRIKE SHALL NOT BE LIABLE TO SOFTWARE USER (UNDER ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STATUTE, TORT OR OTHERWISE) FOR: (A) ANY LOST PROFITS, REVENUE, OR SAVINGS, LOST BUSINESS OPPORTUNITIES, LOST DATA, OR SPECIAL, INCIDENTAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, EVEN IF CROWDSTRIKE HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES OR LOSSES OR SUCH DAMAGES OR LOSSES WERE REASONABLY FORESEEABLE; OR (B) AN AMOUNT THAT EXCEEDS IN THE AGGREGATE $100. THESE LIMITATIONS WILL APPLY NOTWITHSTANDING ANY FAILURE OF ESSENTIAL PURPOSE OF ANY REMEDY SPECIFIED IN THESE TERMS. MULTIPLE CLAIMS SHALL NOT EXPAND THE LIMITATIONS SPECIFIED IN THIS SECTION 7"
It also says:
"For Software Users Outside the United States and Australia. Some countries, states and provinces, including member states of the European Economic Area, do not allow certain exclusions or limitations of liability, therefore, the exclusions or limitation of liabilities and disclaimers of warranties in these Terms may not fully apply to Software User if the laws directly applicable to CrowdStrike in the performance under these Terms do not allow such terms"
https://www.crowdstrike.com/software-terms-of-use/
If I'm understanding that correctly Crowdstrike, or Microsoft, will likely face massive claims for losses in the EU.
I was pondering if Crowdstrike may also be liable in the US due to rolling out a faulty update, and breaking something that was effectively working ok; The end users didn't update the software manually, Crowdstrike automatically upgraded customers without their knowledge or participation, so I do wonder what arguments the Lawyers might use against Crowdstrike for consequential losses due to the outage; As an example Airlines will have to compensate their customers, but they'd argue it wasn't their fault it was Crowdstrike's fault,