My guess: Because they reviewed and signed the kernel space code which calls code that is unreviewed and unsigned (or, at the very least, pulls directly from files that are unreviewed and unsigned without proper validation or error checking), calling out CrowdStrike’s failure puts them on the hook too.
Oh my god, thank you so much for this. I have always had the hardest time finding these exact same requirements, and this is perfect. All metal construction and coexisting with keys has always been a priority for me, but it seems like everyone is inexplicably fine with copping out by just dangling their data on this flimsy little string tied to a brittle plastic case and I cannot understand it.
I’m not currently looking for one at this exact moment, but I will be returning here when I am. You’re doing the lord’s work out here!