Live data from Hacker News

Palo Alto Networks sends cease-and-desist letter to take down review videos

orca.security

91–100 of 135 posts

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#91

Palo Alto networks also makes bossware so intrusive that it's basically malware. Their VPN software on MacOS, for example, collects tons of system data and starts itself persistently on reboot + cannot be quit unless the user happens to have much-more-technical-than-most-users levels of knowledge about things like sudo and the various plist files work. My own experience, in a couple Twitter threads: https://mobile.tw…

It also uses High-Performance graphics for whatever reason when connected and can completely drain a full MacBook Pro battery in under an hour. Disconnecting does not free the GPU. On a positive note, I now have a reason to use to MacBook touchbar. Setup an Automator action to kill the PIDs to release the GPU when I no longer need to use VPN.

I've determined based on trial and error that the High-Performance graphics usage only happens after the animation during the Okta Verify window in their embedded browser. Unfortunately, there's no way for me to disable that and still authenticate into the VPN.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#92

Prisma cloud (the cloud monitoring part) is not a great product. It lags pretty far behind cloud provider capabilities. I also got the email that orca probably sent to everyone in their CRM about this, and while I didn’t need any reason to think less of prisma, I now associate Orca as a competitor and probably an earlier call than palo alto for cloud.

We are considering prisma cloud to monitor an on premise kubernetes deployment. Is there anything I should be concerned about or better options to consider?

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#93

I am grateful to Palo Alto for the C&D. I had them on my radar screen for possible consideration next year on a large project. Now I don't anymore. That's a bunch of money that will go to someone else. This is the price when you have to defend the technical aspects of your solution with lawyers.

This is such an absurd take that I clicked your account to ensure you were not a troll. PAN, for all their true issues, puts out some impressive products. There is a reason they have eaten Checkpoint and Cisco FirePOWER's lunch. Hilariously, my company blocks the article because it is a non-approved TLD. But I challenge you to defend the lawyers and ethics of other large infosec players.

> PAN, for all their true issues, puts out some impressive products. There is a reason they have eaten Checkpoint and Cisco FirePOWER's lunch.

"Better than Cisco" is some pretty strong damning with faint praise.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#94
post #46

Earlier quoted context omitted.

We were just in the process of surveying firewalls. PANW was high on the list, given the user experience. They are no longer on it since today.

I'll say this again, I said it elsewhere. And to clarify, I own no stock in PANW, I don't work for them, though I have years of experience managing PAN firewalls in a large deployment (and some experience with their competitors). My coworkers don't know my HN name so I'm saying this from the heart, not for kudos from meatspace. As part of a team choosing a new technology for something, you really need to take a lot o…

The question isn't "how likely is it that PA is going to sue us", but "how bad do your products have to be that you resort to legal threats to prevent people from doing benchmarks"?

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#95
post #47

Palo Alto networks also makes bossware so intrusive that it's basically malware. Their VPN software on MacOS, for example, collects tons of system data and starts itself persistently on reboot + cannot be quit unless the user happens to have much-more-technical-than-most-users levels of knowledge about things like sudo and the various plist files work. My own experience, in a couple Twitter threads: https://mobile.tw…

As much as I despise this kind of software as an end-user the data collection can be for above-board purposes and is required in certain regulatory domains. Zero excuse for being a shitty application though. In our case we were required to verify that any machine that connected to our VPN was sufficiently updated, had a backup taken, was running AV and was recently scanned for malware, and had disk encryption enabled…

Regulations (I'm familiar with HIPAA/SOX/PCI) do not require specific technical implementations like this. These are just things that have been negotiated between IT and their auditor. Saying shitty IT policies are due to "regulation" is almost always a cop-out.

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#96
post #90

Earlier quoted context omitted.

Have you yourself used the interface for configuration of these options? How easy is it for a non-expert to determine what the vpn client will or will not do, once deployed?

It isn’t. You will have to speak with the IT staff to understand how they have it configured. If you have an issue with this use a third party open source client. The point is, any enterprise client is expected to have these features. Don’t install them on your personal laptop if you have a problem with what is expected behavior.

> The point is, any enterprise client is expected to have these features

"Features" seems like an excessively charitable word to describe spyware/malware-like behavior.

Expected by whom? Certainly not library patrons. On the contrary, library patrons expect their privacy to be protected.

http://www.ala.org/advocacy/privacy

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#97
post #72

Earlier quoted context omitted.

That's really gross. But it is sadly not at all unusual. In fact, Google's obscurely named "Keystone Agent" isn't much better. Apple should expose services in Control Center instead of making you use the terminal.

> Apple should expose services in Control Center instead of making you use the terminal. Especially given how obtuse launchctl is to work with compared to it’s Windows and Linux counterparts.

Is it really that bad? launchctl (load|unload) doesn't seem to hard to use…

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#98

Palo Alto networks also makes bossware so intrusive that it's basically malware. Their VPN software on MacOS, for example, collects tons of system data and starts itself persistently on reboot + cannot be quit unless the user happens to have much-more-technical-than-most-users levels of knowledge about things like sudo and the various plist files work. My own experience, in a couple Twitter threads: https://mobile.tw…

If anyone is required to use Palo Alto or any other closed source VPN, try using Openconnect [1]. It is an open source client for Palo Alto, Cisco, Juniper, etc. VPNs which typically are just cruft on top of IPSEC tunnels. While some of the features these VPNs offer sound cool but at the end of the day they use client side validation in the from of a 'trojan' binary that is downloaded and collects a bunch of metadata about your system. Obviously this can be spoofed pretty easily if you have full control of the machine. I know it works on Linux and it should work on Mac, and Windows.

With some tweaking you can also use it to configure a split tunnel (at least on Linux) VPN so that your employer can't spy on all of your web activity. (Really for any VPN you just need to update the routing table after the VPN software is running).

[1] https://gitlab.com/openconnect/openconnect

Re: Palo Alto Networks sends cease-and-desist letter to take down review videos

#100
post #6

Earlier quoted context omitted.

I've used Palo Alto, Fortinet, and Cisco firewalls. Cisco is the worst by far, the Fortinet are not fun to use but have an incredible $/performance ratio, and the Palo Alto ones are by far the most expensive but also the most enjoyable to use. They're certainly not without their faults, and we've had issues with them that took time to remedy, but I wouldn't trade them for anything else I've seen so far from competito…

Did you just publish the result of a benchmark or performance comparison test you ran to establish the difference in $/performance ratio between competitors? If so, I have bad news for your license compliance...

That's a good thing to warn people of, but feels like a complete red flag in a license. If a company isn't willing to stand by their product in reviews, then that should be a reason to disqualify their product from consideration.
Post reply on HN