Live data from Hacker News

Palo Alto Networks sends cease-and-desist letter to take down review videos

orca.security

111–120 of 135 posts

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#111

Earlier quoted context omitted.

That presumes a lawyer will give you good legal advice. I've been given poor legal advice before by a lawyer, and been given even worse tactical advice. I've gone against a lawyer's recommendations before when their explanation and recommendation did not jive with my reading and understanding. You should educate yourself and seek counsel if you believe you need it. Because ultimately the situation is no different tha…

> But a lawyer's opinion, even if it's a good opinion, doesn't inoculate you from being sued or threatened or whatever else an antagonizing party may do. Actually, "reliance on advice of counsel" is a valid legal defense. It's an interesting legal privilege lawyers have given themselves.

(IAAL but this is not legal advice.)

Reliance on advice of counsel is not a blanket defense against any arbitrary crime you could be charged with or civil liability you might face. It is only a defense in a certain limited set of circumstances; and it also requires you to waive attorney-client privilege.

See https://digitalcommons.law.yale.edu/cgi/viewcontent.cgi?arti... for a good, if dated, overview of the law.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#112

Earlier quoted context omitted.

That presumes a lawyer will give you good legal advice. I've been given poor legal advice before by a lawyer, and been given even worse tactical advice. I've gone against a lawyer's recommendations before when their explanation and recommendation did not jive with my reading and understanding. You should educate yourself and seek counsel if you believe you need it. Because ultimately the situation is no different tha…

Can you expand on how one would educate themselves on this (besides getting a law degree), and how one would determine that they need legal counsel, besides having this vague feeling that they need it? Are there some rules of thumb that a normal, non-lawyer can follow to roughly gauge the seriousness of a written legal threat?

A good rule of thumb is that when an attorney sends you a cease and desist letter, you should hire an attorney to read it and give you advice on what to do and/or how to respond -- especially if you are inclined not to assent to the demands made.

I know this, not only as an attorney today, but as someone who (before I got my law degree) did not do this and paid a very high price for my immaturity. Hiring an attorney could have saved me many thousands of dollars.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#113
post #104

Earlier quoted context omitted.

> Expected by whom? By the people who pay Palo Alto Networks.

No, people who pay for Spyware to spy on their employers / users.

Right. The people who pay Palo Alto Networks, in other words.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#114
post #104

Earlier quoted context omitted.

No, people who pay for Spyware to spy on their employers / users.

Let's lay this out. Let's say you are a government IT shop (it doesn't matter what level, state, nation whatever), or a bank, or a hospital, you are required by law to control how data is processed on your network. Therefore you must monitor compliance for devices connecting to your network. This is what GlobalProtect was designed for. It can be used in less restrictive environments, but the IT shop should make sure…

Right, Global Protect is great in regulated environments. You can turn on its always on functionality and devices can then be used while connected to VPN or not at all. If that setting is configured in an environment where users are connecting their personal devices, it's misconfigured, pure and simple.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#115
post #71
post #58

The title is deceptive. OP is not some independent site doing a neutral review. This is a competitor pretending to be neutral (and doing a laughably bad job at it; the "referee" is their evangelist). So they basically make a untrustworthy video that (surprise, surprise) comes to the conclusion that their product is better, provoke Palo Alto into a hamfisted knee-jerk response, and now try to drum up cheap publicity b…

Fefe, We never said we're objective. Marketing is almost never objective. We tried to make it objective, but naturally - we're biased. But should the larger player be allowed to stop the smaller one from publishing his materials?

So the more accurate title should be "Palo Alto Networks sends cease-and-desist letter to take down comparative advertisement"?

Not that I agree with Palo Alto's lawyer, I just don't like misleading titles.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#116

I am grateful to Palo Alto for the C&D. I had them on my radar screen for possible consideration next year on a large project. Now I don't anymore. That's a bunch of money that will go to someone else. This is the price when you have to defend the technical aspects of your solution with lawyers.

My first thought was I saw this thread was the Barbara Streisand effect. My employer uses GP, but at least I learned about mitigation from this thread, such as OpenConnect.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#117
post #47

Earlier quoted context omitted.

As much as I despise this kind of software as an end-user the data collection can be for above-board purposes and is required in certain regulatory domains. Zero excuse for being a shitty application though. In our case we were required to verify that any machine that connected to our VPN was sufficiently updated, had a backup taken, was running AV and was recently scanned for malware, and had disk encryption enabled…

Anyone who requires this level of security for regulatory purposes should not have a BYOD policy at all. "Only fully-managed, organization-owned devices get to touch this data" is the only fair way to both maintain data security in highly regulated environments and not effectively take ownership over employees (and, in a university context, student) computers).

Agreed. Enterprise 802.1X NAC policies are not compatible with BYOD users.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#118

Earlier quoted context omitted.

If anyone is required to use Palo Alto or any other closed source VPN, try using Openconnect [1]. It is an open source client for Palo Alto, Cisco, Juniper, etc. VPNs which typically are just cruft on top of IPSEC tunnels. While some of the features these VPNs offer sound cool but at the end of the day they use client side validation in the from of a 'trojan' binary that is downloaded and collects a bunch of metadata…

Oh, how interesting! Thanks for linking this. I'd love to hear if anyone has experience with it---slightly anxious about using unknown software for sensitive tasks like VPN, but it does look like a pretty robust project...

Used it since my employer rolled out Palo Alto in March. Zero problems and it was really easy to setup.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#119

Earlier quoted context omitted.

My wife went to law school. I know lots of lawyers. The spread between Justin (first in his class by a fat margin), and the bottom, oh, say, quarter of the class, is brutal.

Question I have... How bad is that lower quarter? Can you quantify that in any way?

Justin relishes a fight; he's confident. He's creative in his thinking. Many lawyers are paper pushers. They file the right documents, fill out the right forms, but they can't think tactically to save their lives. They're never going to change the outcome of a case.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#120
post #8
post #4

Earlier quoted context omitted.

This. Many lawyers threaten and posture for a living. Don't let their empty threats bully you into submission if you've done nothing wrong.

Palo Alto can easily cause us to put 500K USD into legal fees, and I guess they thought that we'll bail out due to this empty threat. We chose not to.

Why/how would they cause you to put that much into legal fees? You don't need to hire an attorney, and probably you can hire anyone (with a legal bar license), right? Just hire the cheapest one. Sure that might not be the brightest tactic, but claiming that they can "cause" this is very strange. (You might even get someone to file motions for you pro bono.)
Post reply on HN