Live data from Hacker News

Palo Alto Networks sends cease-and-desist letter to take down review videos

orca.security

101–110 of 135 posts

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#101
post #90

Earlier quoted context omitted.

It isn’t. You will have to speak with the IT staff to understand how they have it configured. If you have an issue with this use a third party open source client. The point is, any enterprise client is expected to have these features. Don’t install them on your personal laptop if you have a problem with what is expected behavior.

> The point is, any enterprise client is expected to have these features "Features" seems like an excessively charitable word to describe spyware/malware-like behavior. Expected by whom? Certainly not library patrons. On the contrary, library patrons expect their privacy to be protected. http://www.ala.org/advocacy/privacy

> Expected by whom?

By the people who pay Palo Alto Networks.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#102

Palo Alto networks also makes bossware so intrusive that it's basically malware. Their VPN software on MacOS, for example, collects tons of system data and starts itself persistently on reboot + cannot be quit unless the user happens to have much-more-technical-than-most-users levels of knowledge about things like sudo and the various plist files work. My own experience, in a couple Twitter threads: https://mobile.tw…

If anyone is required to use Palo Alto or any other closed source VPN, try using Openconnect [1]. It is an open source client for Palo Alto, Cisco, Juniper, etc. VPNs which typically are just cruft on top of IPSEC tunnels. While some of the features these VPNs offer sound cool but at the end of the day they use client side validation in the from of a 'trojan' binary that is downloaded and collects a bunch of metadata…

Oh, how interesting! Thanks for linking this. I'd love to hear if anyone has experience with it---slightly anxious about using unknown software for sensitive tasks like VPN, but it does look like a pretty robust project...

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#103
post #72

Earlier quoted context omitted.

That's really gross. But it is sadly not at all unusual. In fact, Google's obscurely named "Keystone Agent" isn't much better. Apple should expose services in Control Center instead of making you use the terminal.

> Apple should expose services in Control Center instead of making you use the terminal. Especially given how obtuse launchctl is to work with compared to it’s Windows and Linux counterparts.

Hmm. I don't know about Windows, but when I've used Linux in the last few years, my impression of systemd is that somebody looked over at Apple's launchd and inexplicably said "yes, that's a great idea, let's do that," then did it just a little bit worse.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#104

Earlier quoted context omitted.

> The point is, any enterprise client is expected to have these features "Features" seems like an excessively charitable word to describe spyware/malware-like behavior. Expected by whom? Certainly not library patrons. On the contrary, library patrons expect their privacy to be protected. http://www.ala.org/advocacy/privacy

> Expected by whom? By the people who pay Palo Alto Networks.

No, people who pay for Spyware to spy on their employers / users.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#105
post #46

Earlier quoted context omitted.

We were just in the process of surveying firewalls. PANW was high on the list, given the user experience. They are no longer on it since today.

I'll say this again, I said it elsewhere. And to clarify, I own no stock in PANW, I don't work for them, though I have years of experience managing PAN firewalls in a large deployment (and some experience with their competitors). My coworkers don't know my HN name so I'm saying this from the heart, not for kudos from meatspace. As part of a team choosing a new technology for something, you really need to take a lot o…

The CTO and I agreed we value honesty and integrity in the companies we work with. On top of that, this is not behavior we want go support. If they pull BS on others, they may pull BS on us one day. It does not give good expectations for how they would handle disclosure surrounding some embarrassing security incident, for one thing.

"Business is business" may have different connotation for different people.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#106

Earlier quoted context omitted.

How do you tell whether you're doing something wrong or not without spending money on your own lawyer?

That presumes a lawyer will give you good legal advice. I've been given poor legal advice before by a lawyer, and been given even worse tactical advice. I've gone against a lawyer's recommendations before when their explanation and recommendation did not jive with my reading and understanding. You should educate yourself and seek counsel if you believe you need it. Because ultimately the situation is no different tha…

> But a lawyer's opinion, even if it's a good opinion, doesn't inoculate you from being sued or threatened or whatever else an antagonizing party may do.

Actually, "reliance on advice of counsel" is a valid legal defense. It's an interesting legal privilege lawyers have given themselves.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#107

Earlier quoted context omitted.

Did you just publish the result of a benchmark or performance comparison test you ran to establish the difference in $/performance ratio between competitors? If so, I have bad news for your license compliance...

Nope, I read the manufacturers published specifications for their equipment and looked up the pricing on publicly accessible websites. https://www.paloaltonetworks.com/products/product-selection https://www.fortinet.com/products/product-compare?cat=ngfw And you can get pricing from any VARs website such as CDW.com Good try though.

That is a performance comparison test; it's just not one that requires access to the hardware.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#108
post #104

Earlier quoted context omitted.

> Expected by whom? By the people who pay Palo Alto Networks.

No, people who pay for Spyware to spy on their employers / users.

Let's lay this out. Let's say you are a government IT shop (it doesn't matter what level, state, nation whatever), or a bank, or a hospital, you are required by law to control how data is processed on your network. Therefore you must monitor compliance for devices connecting to your network. This is what GlobalProtect was designed for. It can be used in less restrictive environments, but the IT shop should make sure to audit the rules and policies of the client to not be overly burdensome on users. Palo Alto has numerous courses to train IT professionals to configure their products. It is on the IT professionals to configure the services correctly.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#109

Earlier quoted context omitted.

I posted this in a comment response below. All of these things are actually configured by the company/library you are connecting to. They are configuration options for the firewall that are enforced by global protect. Blame your library IT, not Palo Alto.

Have you yourself used the interface for configuration of these options? How easy is it for a non-expert to determine what the vpn client will or will not do, once deployed?

Yes, I have. That interface is not for non-experts. It is for the IT professionals configuring the portal.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#110

Earlier quoted context omitted.

If anyone is required to use Palo Alto or any other closed source VPN, try using Openconnect [1]. It is an open source client for Palo Alto, Cisco, Juniper, etc. VPNs which typically are just cruft on top of IPSEC tunnels. While some of the features these VPNs offer sound cool but at the end of the day they use client side validation in the from of a 'trojan' binary that is downloaded and collects a bunch of metadata…

Oh, how interesting! Thanks for linking this. I'd love to hear if anyone has experience with it---slightly anxious about using unknown software for sensitive tasks like VPN, but it does look like a pretty robust project...

I’ve been using it for years now. I have a Debian vm that is configured as a NATing router so I can flexibly send traffic wherever I want. Also use unbound to use the company dns for company internal queries only. With the particular Palo Alto config the company uses I need to peel a cert off of a windows domain member as well as my creds, but that’s not hard to manage
Post reply on HN