Once again you seem to be calling for not bothering with any security effort of there’s even a remote chance of some other vulnerability happening.
The whole point of security is that it’s always a multi-layered thing. Nobody sane is pretending that encrypting web traffic with HTTPS is a panacea that’s going to solve all your data security needs. But it is sure as hell a million times better than having all of your data transmitted in the clear, with absolutely no assurance that you’re are talking to the system you think you’re talking to, or that the data hasn’t been tampered with in transit.
And don’t pretend https is a huge burden. It’s dead simple to get SSL/TLS certs, and the additional load of encrypting and decrypting the traffic is barely even a rounding error on modern CPUs.
Exactly, the blame here is entirely on Crowdstrike. they could just as easily have made similar mistake in an update for the Linux agent that would crash the system and bring down half the planet.
I will say, the problem MIGHT have been easier to fix or work around on the Linux systems.