Live data from Hacker News

Palo Alto Networks sends cease-and-desist letter to take down review videos

orca.security

61–70 of 135 posts

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#61
post #46

Earlier quoted context omitted.

We were just in the process of surveying firewalls. PANW was high on the list, given the user experience. They are no longer on it since today.

I'll say this again, I said it elsewhere. And to clarify, I own no stock in PANW, I don't work for them, though I have years of experience managing PAN firewalls in a large deployment (and some experience with their competitors). My coworkers don't know my HN name so I'm saying this from the heart, not for kudos from meatspace. As part of a team choosing a new technology for something, you really need to take a lot o…

I suspect in this case it's not because of the single review, but because of the shady business practices.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#62

I am grateful to Palo Alto for the C&D. I had them on my radar screen for possible consideration next year on a large project. Now I don't anymore. That's a bunch of money that will go to someone else. This is the price when you have to defend the technical aspects of your solution with lawyers.

This is such an absurd take that I clicked your account to ensure you were not a troll. PAN, for all their true issues, puts out some impressive products. There is a reason they have eaten Checkpoint and Cisco FirePOWER's lunch. Hilariously, my company blocks the article because it is a non-approved TLD. But I challenge you to defend the lawyers and ethics of other large infosec players.

I agree. If you have a full time security analyst(s) to tune and monitor it, PA's firewall is unbeatable for perimeter security AFAIK. Unfortunately, their other offerings don't measure up and tend to be a jumble of M&A.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#63
post #47

Palo Alto networks also makes bossware so intrusive that it's basically malware. Their VPN software on MacOS, for example, collects tons of system data and starts itself persistently on reboot + cannot be quit unless the user happens to have much-more-technical-than-most-users levels of knowledge about things like sudo and the various plist files work. My own experience, in a couple Twitter threads: https://mobile.tw…

As much as I despise this kind of software as an end-user the data collection can be for above-board purposes and is required in certain regulatory domains. Zero excuse for being a shitty application though. In our case we were required to verify that any machine that connected to our VPN was sufficiently updated, had a backup taken, was running AV and was recently scanned for malware, and had disk encryption enabled…

Anyone who requires this level of security for regulatory purposes should not have a BYOD policy at all. "Only fully-managed, organization-owned devices get to touch this data" is the only fair way to both maintain data security in highly regulated environments and not effectively take ownership over employees (and, in a university context, student) computers).

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#64
post #46

Earlier quoted context omitted.

We were just in the process of surveying firewalls. PANW was high on the list, given the user experience. They are no longer on it since today.

I'll say this again, I said it elsewhere. And to clarify, I own no stock in PANW, I don't work for them, though I have years of experience managing PAN firewalls in a large deployment (and some experience with their competitors). My coworkers don't know my HN name so I'm saying this from the heart, not for kudos from meatspace. As part of a team choosing a new technology for something, you really need to take a lot o…

Is your heart telling you that you should get people to buy the product you've got professional experience with?

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#65
post #9

The letter is about using Palo Alto Networks trademarks on their website. I think Orca should just change their review to say "Palo Crapo Networks" .... issue solved

Or a new diet, Paleo Alto

Or the slightly deeper Palo Tenor.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#66

Palo Alto networks also makes bossware so intrusive that it's basically malware. Their VPN software on MacOS, for example, collects tons of system data and starts itself persistently on reboot + cannot be quit unless the user happens to have much-more-technical-than-most-users levels of knowledge about things like sudo and the various plist files work. My own experience, in a couple Twitter threads: https://mobile.tw…

That's really gross. But it is sadly not at all unusual. In fact, Google's obscurely named "Keystone Agent" isn't much better.

Apple should expose services in Control Center instead of making you use the terminal.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#67

Palo Alto networks also makes bossware so intrusive that it's basically malware. Their VPN software on MacOS, for example, collects tons of system data and starts itself persistently on reboot + cannot be quit unless the user happens to have much-more-technical-than-most-users levels of knowledge about things like sudo and the various plist files work. My own experience, in a couple Twitter threads: https://mobile.tw…

I posted this in a comment response below.

All of these things are actually configured by the company/library you are connecting to. They are configuration options for the firewall that are enforced by global protect. Blame your library IT, not Palo Alto.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#68
post #36

Earlier quoted context omitted.

Just google 'yelp law'. It isn't legal these days.

You mean CRFA? https://www.ftc.gov/tips-advice/business-center/guidance/con... Did a court rule that CRFA trumps (npi) DeWitt's Clause? https://dwheeler.com/essays/dewitt-clause.html (IANAL)

IAAL, and that is a good question. (This is not legal advice.)

CRFA appears to apply to contracts that bind an "individual" and not a "person". This technical difference is important in contracts: an individual is also known in the art as a "natural person" (i.e., a human being), while a "person" could be an individual, a company, or other organization.

So it is possible that the law does not apply to Orca Security because they are a "person" and not an "individual". In other words, if it can be found that Mr. Shua was acting as an officer or other representative of Orca Security instead of in his personal capacity, then CRFA may not apply to the license agreement.

Again, this is NOT legal advice, and anyone seeking a legal opinion should engage a licensed attorney. This law is pretty new and I don't know whether this specific question has been tested by any court. But I would tread with caution.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#69

> Palo Alto Networks appears oblivious to the fact that the New York Attorney General’s office sued and won an injunction against McAfee from enforcing its contractual restrictions against publishing reviews or comparisons of its products without its consent more than 17 years ago. In enacting the Consumer Review Fairness Act, Congress has also prohibited businesses from including contract terms that prohibit consume…

Maybe, maybe not. See my analysis elsewhere about the importance of the word "individual" as opposed to "person" in the language of CFRA.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#70
post #34

Earlier quoted context omitted.

Most likely than not, they have legal basis for what they are asking for. Check with your lawyers and if they agree, you should just accept and move on. The distraction (and cost) of having to fight a legal battle to have a comparison page on your website is just not worth it for most startups. We are a tiny company building an open-source alternative to an existing SaaS app and we have received two such letters in t…

We checked VERY thoroughly. They don't have legal basis. Federal law specifically prohibit clauses that prevent open reviews. It is dubbed the 'yelp law'

I would double check that legal advice (assuming you actually consulted a competent attorney who specializes in this law). See my analysis elsewhere in this discussion.
Post reply on HN