10 ms·
Palo Alto Networks sends cease-and-desist letter to take down review videos
- cybert00th 6y agoOur firewall guy thinks Palo Alto firewalls are really good and I don't dispute that they are. But I may just show him this tomorrow morning as, another perspective never hurts.
- RKearney 6y agoI've used Palo Alto, Fortinet, and Cisco firewalls. Cisco is the worst by far, the Fortinet are not fun to use but have an incredible $/performance ratio, and the Palo Alto ones are by far the most expensive but also the most enjoyable to use. They're certainly not without their faults, and we've had issues with them that took time to remedy, but I wouldn't trade them for anything else I've seen so far from competitors.
- canarypilot 6y agoDid you just publish the result of a benchmark or performance comparison test you ran to establish the difference in $/performance ratio between competitors? If so, I have bad news for your license compliance...
- RKearney 6y agoNope, I read the manufacturers published specifications for their equipment and looked up the pricing on publicly accessible websites. https://www.paloaltonetworks.com/products/product-selection https://www.paloaltonetworks.com/products/product-selection https://www.fortinet.com/products/product-compare?cat=ngfw https://www.fortinet.com/products/product-compare?cat=ngfw And you can get pricing from any VARs website such as CDW.com Good try though.
- thaumasiotes 6y agoThat is a performance comparison test; it's just not one that requires access to the hardware.
- RKearney 6y agoTheir performance test, not mine. I'm going off the numbers they cited.
- MereInterest 6y agoThat's a good thing to warn people of, but feels like a complete red flag in a license. If a company isn't willing to stand by their product in reviews, then that should be a reason to disqualify their product from consideration.
- pmart123 6y agoHave you ever worked with Check Point's firewall?
- guardiangod 6y agoCheck out https://www.reddit.com/r/networking/ https://www.reddit.com/r/networking/ and search for the firewall/company names, sorted by Newest. (I don't subscribe to the sub nor have I posted anything in it. I do read it from time to time and find the comments alright from an end-user (ie. sysadmin) point of view.)
- pmart123 6y agoThanks.
- bnjms 6y agoFWIW, I know a Checkpoint guy and he swears they’re the best. I haven’t had a chance to do a comparison with him yet but the impression I get is that Checkpoint gets overlooked more than anything so they don’t do great on r/networking. There is another guy in this thread who gives a good review saying Checkpoint got good in response to competition. Forti is the value option. And, FTD is looked down upon while ASA has some niches. So, PAN, Checkpoint, and Fortinet appears to be the leaders.
- codingdave 6y agoLawyers sending letters to discourage actions they do not like are fairly standard. I've had attorneys tell me that if you are not getting letters like this, you aren't making enough of an impact. And to be clear, this is just a letter - tossing one of these out just to see if it works is an easy tactic because many smaller organizations are terrified of litigation, and will cave to demands even if there is no legal basis for them. Do take the letters seriously... determine whether there are valid legal claims presented. But if there are not, it is a scare tactic, so don't stress over it.
- trentnix 6y agoThis. Many lawyers threaten and posture for a living. Don't let their empty threats bully you into submission if you've done nothing wrong.
- shuaavi 6y agoPalo Alto can easily cause us to put 500K USD into legal fees, and I guess they thought that we'll bail out due to this empty threat. We chose not to.
- pas 6y agoWhy/how would they cause you to put that much into legal fees? You don't need to hire an attorney, and probably you can hire anyone (with a legal bar license), right? Just hire the cheapest one. Sure that might not be the brightest tactic, but claiming that they can "cause" this is very strange. (You might even get someone to file motions for you pro bono.)
- otterley 6y ago> Just hire the cheapest one. Do you know what they call the person who graduated at the bottom of their law school class? "Counselor." Do not hire the cheapest lawyer you can find. The amount of work required to analyze this situation is a few hours at most; and the hourly-rate difference between a good lawyer and a bad lawyer is going to be far less than what it will cost you if you get bad advice. > You might even get someone to file motions for you pro bono No attorney worth a damn is going to provide a commercial entity pro bono representation.
- orca-pp 6y agoWith NSS Labs shutting down today the need for objectivity and visibility into testing has never been greater.
- guardiangod 6y agoI know no one cares about NSS Labs but as an employee of a NSS-tested company I'd like to say RIP. No one does testing as rigorously as you, and thanks for all the headaches you've caused my teams. (Gartner is a joke. There, I said it.)
- bonfire 6y ago:) Same here
- kazen44 6y agoNSS labs was one of the few labs which actually did rigorous testing in regards to firewall performance. It helped me and my company enourmously with both recommending solutions to customers aswell as troubleshooting. Mainly by providing a truthfull baseline compared to the datasheet of the vendor. all firewall vendors seem to basically lie on their datasheet in regards to real life performance. This becomes a real pain in the arse when you start seeing performance issues or weird behaviour because you actually run a firewall "to spec". a good example of this was a cisco asa with firepower (which in itself ia a terrible solution, but alas). even at "just" 50% of the specced load, we started seeing weird issues in regards to IPsec tunnels. (SA's randomly dropping, getting abysmal performance at certain times etc).
- orliesaurus 6y agoI applaud Orca security to expose the bs that Palo Alto Networks is trying to feed the enterprise security industry - as other comments have said, these are fairly standard, but you could have just not said anything and moved on...instead you come out and explain the situation. I love this transparency!
- shuaavi 6y agoThanks !!!
- cycop 6y agoThe letter is about using Palo Alto Networks trademarks on their website. I think Orca should just change their review to say "Palo Crapo Networks" .... issue solved
- yoavalon 6y agoOr a new diet, Paleo Alto
- robertlagrant 6y agoOr the slightly deeper Palo Tenor.
- dvtrn 6y agoThat’s a great pitch.
- zufallsheld 6y agoIt's says "orcas comparison and rating of prisma and its public dissemination is a clear breach of...", so not just a trademark issue.
- robertab 6y agoI'm curious as to what Palo Alto is concerned about with these videos. If they feel they are mis-represented, they can easily post their own videos in response. But no doubt, transparency is a necessity and cease-and-desist letters does no one any good.
- dylan604 6y agoHuh? If it causes the video giving bad reviews of their product to be taken down, the C&D letter does a lot of good for Palo Alto. Even if the review is accurate, if Palo Alto can force the review to go away it is a good day's work for that lawyer.
- hinkley 6y agoUnless you trigger the Streisand Effect. But it looks like more people have upvoted this post than actually watched the video, so maybe that isn’t going to happen.
- dylan604 6y agoWhile the Streisand Effect might be valid, I am curious if lawyers give a crap about it. If more people start posting the same content and/or similar but equally aggravating content, then that's just more work for the lawyers to do. More billable hours. They'll just have an intern or do it.
- logicalmonster 6y agoA review seems like a textbook case of fair use to me. Not sure where there’s a justification for removing a review in this situation.
- kmeisthax 6y agoBecause of a legal precedent and a general fact about contract law: 1. Installation and/or execution of software constitutes copying (the "RAM Copy Doctrine") which is only lawful if the person currently using the software has been licensed or sold the software 2. Licensing restrictions can restrict license holders from exercising rights they otherwise would have as a matter of law There is nothing prohibiting you from only licensing your software out under terms that prohibit licensees from exercising fair use or first sale rights. Indeed, this is one of Oracle's main "innovations": ever since Larry Ellison failed to get David DeWitt fired for daring to benchmark Oracle, they just made everyone who buys Oracle promise not to benchmark it. This is legally sound and the only way around it is to argue that the software transaction was actually a sale and not a license - as far as I'm aware, though, nobody has been able to successfully articulate such a claim.
- shuaavi 6y agoJust google 'yelp law'. It isn't legal these days.
- eternalban 6y agoYou mean CRFA? https://www.ftc.gov/tips-advice/business-center/guidance/consumer-review-fairness-act-what-businesses-need-know https://www.ftc.gov/tips-advice/business-center/guidance/con... Did a court rule that CRFA trumps (npi) DeWitt's Clause? https://dwheeler.com/essays/dewitt-clause.html https://dwheeler.com/essays/dewitt-clause.html (IANAL)
- otterley 6y agoIAAL, and that is a good question. (This is not legal advice.) CRFA appears to apply to contracts that bind an "individual" and not a "person". This technical difference is important in contracts: an individual is also known in the art as a "natural person" (i.e., a human being), while a "person" could be an individual, a company, or other organization. So it is possible that the law does not apply to Orca Security because they are a "person" and not an "individual". In other words, if it can be found that Mr. Shua was acting as an officer or other representative of Orca Security instead of in his personal capacity, then CRFA may not apply to the license agreement. Again, this is NOT legal advice, and anyone seeking a legal opinion should engage a licensed attorney. This law is pretty new and I don't know whether this specific question has been tested by any court. But I would tread with caution.
- paultopia 6y agoPalo Alto networks also makes bossware so intrusive that it's basically malware. Their VPN software on MacOS, for example, collects tons of system data and starts itself persistently on reboot + cannot be quit unless the user happens to have much-more-technical-than-most-users levels of knowledge about things like sudo and the various plist files work. My own experience, in a couple Twitter threads: https://mobile.twitter.com/PaulGowder/status/1296932684707631109 https://mobile.twitter.com/PaulGowder/status/129693268470763... https://mobile.twitter.com/PaulGowder/status/1296865245521223680 https://mobile.twitter.com/PaulGowder/status/129686524552122... Tl;dr: I installed their VPN software on my personal computer in order to get remote library database access during COVID. It turns out that it wanted to know everything about my system and I had to rip holes into configuration files 99% of users couldn't even find in order to stop it.
- ecliptik 6y agoIt also uses High-Performance graphics for whatever reason when connected and can completely drain a full MacBook Pro battery in under an hour. Disconnecting does not free the GPU. On a positive note, I now have a reason to use to MacBook touchbar. Setup an Automator action to kill the PIDs to release the GPU when I no longer need to use VPN.
- justinclift 6y agoMaybe their developers don't yet know that's fixable with a plist entry? eg: https://github.com/sqlitebrowser/sqlitebrowser/commit/72a4524a368a1f28d73c4ba065d2695342568be8 https://github.com/sqlitebrowser/sqlitebrowser/commit/72a452... You can manually add that to applications that don't have it, to see if it works. :)
- oplav 6y agoI've determined based on trial and error that the High-Performance graphics usage only happens after the animation during the Okta Verify window in their embedded browser. Unfortunately, there's no way for me to disable that and still authenticate into the VPN.
- cnst 6y ago
- hirundo 6y agoDear Palo Alto Networks: There is no way I would have watched that video if you hadn't demanded it be taken down. Now having watched it I can see why you want to hide it.
- mshook 6y agoTypical case of https://en.wikipedia.org/wiki/Streisand_effect https://en.wikipedia.org/wiki/Streisand_effect
- 3np 6y agoWe were just in the process of surveying firewalls. PANW was high on the list, given the user experience. They are no longer on it since today.
- unethical_ban 6y agoI'll say this again, I said it elsewhere. And to clarify, I own no stock in PANW, I don't work for them, though I have years of experience managing PAN firewalls in a large deployment (and some experience with their competitors). My coworkers don't know my HN name so I'm saying this from the heart, not for kudos from meatspace. As part of a team choosing a new technology for something, you really need to take a lot of things into consideration. This would be one thing your legal department would need to consider, undoubtedly. However, if you are trying to choose such a critical technology as your infosec stack, and you completely remove a company from a bakeoff because of a negative review (which this essentially is), then you are not running your bakeoff properly. PA firewalls and systems are pretty freaking good. I haven't worked with Checkpoint for a long time, but hear they got good a few years back when PA started eating their lunch. FirePOWER is the devil, as is Cisco.
- azernik 6y agoI suspect in this case it's not because of the single review, but because of the shady business practices.
- robertlagrant 6y ago
- AcerbicZero 6y agoThats a silly lawyer move, but I also kind of understand where PA is coming from - the FW space is a crowded, reputation driven world and a lot of classic late 00s companies are struggling to adapt to a less hardware centric space. That said, build better products, don't take down crappy reviews. I've had terrific experiences with my PA FW's and Panorama isn't too shabby as far as centralized mgmt solutions go - I'd hate to see them throw away all the good will they've built up with stupid choices like this.
- RIMR 6y agoIt's not just about the reviews. People make careers out of reviewing products. Legal complaints can lead to people be demonetized or deplatformed entirely. For PA to risk ruining other people's careers (for being honest!) just to artificially inflate the reputation of their own crappy product isn't something I can forgive very easily.
- cddotdotslash 6y agoThis entire saga literally has nothing to do with firewalls.
- trhway 6y ago>In enacting the Consumer Review Fairness Act, Congress has also prohibited businesses from including contract terms that prohibit consumers from reviewing products or services they purchase. [IANAL] if that is true i wonder whether PA Networks exposes itself to counter suit as i think i know at least one similar (in my layman view) case where inclusion and enforcement of a contract provision violating a specific consumer law protection provision was a ground for successful class action. In such a case one doesn't even need to actually fight the legal battle themselves, just show it to lawyers with time to spare, and even just mentioning such possibility may be enough on its own.
- RIMR 6y agoAt this point in the game, how could anyone ever think that this was a good idea? Palo Alto Networks is already on my blacklist because of how badly their products perform in production. This makes it hard for me to ever consider them again, since it's clear that they are trying to purge negative information about their product from my view.
- neilv 6y agoTrustworthiness seems to be one of the most important properties of a firewall company. But this news of a reviewer getting cease&desist nastygram from PANW erodes some of the trust that PANW started with by default in my mind. They're not the only company to try to prevent independent benchmarking and reviews, but I've never liked that from any company. Perhaps this could be a learning moment for PANW, and they decide to change some policies? (I actually have one of those big old Palo Alto Networks blue rackmount firewalls right here, purchased with the intention of playing with it, either for ideas for OpenWrt features, or to decide whether to buy a new little one for interim use until I have more time for open source. I'm not getting much warm-fuzzies from the big blue metal box at the moment, but maybe that will improve.)
- BrandoElFollito 6y agoI am grateful to Palo Alto for the C&D. I had them on my radar screen for possible consideration next year on a large project. Now I don't anymore. That's a bunch of money that will go to someone else. This is the price when you have to defend the technical aspects of your solution with lawyers.
- quadrifoliate 6y agoYep, they just dropped out of consideration as a firewall vendor for me in the near future. The money for this superfluous legal stuff is coming from somewhere, probably from the overinflated margins. Also no one wants to be sued by a company whose products you paid good money for.
- unethical_ban 6y agoThis is such an absurd take that I clicked your account to ensure you were not a troll. PAN, for all their true issues, puts out some impressive products. There is a reason they have eaten Checkpoint and Cisco FirePOWER's lunch. Hilariously, my company blocks the article because it is a non-approved TLD. But I challenge you to defend the lawyers and ethics of other large infosec players.
- GartzenDeHaes 6y agoI agree. If you have a full time security analyst(s) to tune and monitor it, PA's firewall is unbeatable for perimeter security AFAIK. Unfortunately, their other offerings don't measure up and tend to be a jumble of M&A.
- yjftsjthsd-h 6y ago> PAN, for all their true issues, puts out some impressive products. There is a reason they have eaten Checkpoint and Cisco FirePOWER's lunch. "Better than Cisco" is some pretty strong damning with faint praise.
- FullyFunctional 6y agoMy first thought was I saw this thread was the Barbara Streisand effect. My employer uses GP, but at least I learned about mitigation from this thread, such as OpenConnect.
- ghastmaster 6y ago> Palo Alto Networks appears oblivious to the fact that the New York Attorney General’s office sued and won an injunction against McAfee from enforcing its contractual restrictions against publishing reviews or comparisons of its products without its consent more than 17 years ago. In enacting the Consumer Review Fairness Act, Congress has also prohibited businesses from including contract terms that prohibit consumers from reviewing products or services they purchase. New York only matters if either party has standing in that jurisdiction. Palo Alto Networks(California) and Orca Security(Israel) would not, however there could be made a case that the video in question resides on servers(youtube) in New York. The argument for the application of 15 U.S. Code § 45b appears to only apply to "form contracts". > means a contract with standardized terms— (i) used by a person in the course of selling or leasing the person’s goods or services; and (ii) imposed on an individual without a meaningful opportunity for such individual to negotiate the standardized terms. It appears as though the EULA is a form contract and Orca indeed falls under the protections of the Consumer Reviews Fairness Act. EULA: https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/legal/palo-alto-networks-end-user-license-agreement-eula.pdf https://www.paloaltonetworks.com/content/dam/pan/en_US/asset...
- otterley 6y agoMaybe, maybe not. See my analysis elsewhere about the importance of the word "individual" as opposed to "person" in the language of CFRA.
- deleted 6y ago[deleted]
- ghastmaster 6y agoGood catch! It looks like the New York case does indeed have some relevance as well considering the code explicitly allows state's attorneys general to file suit using this statute. Because it did not proceed to the higher courts(that I know of) it is not of great significance, but still noteworthy.
- 6y ago
- deleted 6y ago[deleted]
- jlgaddis 6y agoDear Palo Alto Networks, In response to your "Cease and Desist" letter of 4 September 2020 to Avi Shua of Orca Security, we refer you to the reply given in the case of Arkell v. Pressdram [0]. Sincerely, The Internet -- [0]: https://lettersofnote.com/2013/08/07/arkell-v-pressdram/ https://lettersofnote.com/2013/08/07/arkell-v-pressdram/
- fefe23 6y agoThe title is deceptive. OP is not some independent site doing a neutral review. This is a competitor pretending to be neutral (and doing a laughably bad job at it; the "referee" is their evangelist). So they basically make a untrustworthy video that (surprise, surprise) comes to the conclusion that their product is better, provoke Palo Alto into a hamfisted knee-jerk response, and now try to drum up cheap publicity by posing as the victim. I have always regarded Palo Alto's products as snake oil, so this is not a fan defending their team. That said: This behavior of Orca is reprehensible and you should not reward them with your attention.
- shuaavi 6y agoFefe, We never said we're objective. Marketing is almost never objective. We tried to make it objective, but naturally - we're biased. But should the larger player be allowed to stop the smaller one from publishing his materials?
- joshl325369 6y agoSo the more accurate title should be "Palo Alto Networks sends cease-and-desist letter to take down comparative advertisement"? Not that I agree with Palo Alto's lawyer, I just don't like misleading titles.
- cddotdotslash 6y agoBear with me here, but what if this entire thing was engineered from the beginning to be a marketing technique? The videos themselves? Marketing. The "we got a cease and desist from a big company" blog? Marketing. The follow-up letter about transparency? Marketing. And it all falls right into the David vs. Goliath story that the tech community loves.
- drakenot 6y agoAre you saying the cease and desist is potentially fabricated? That seems unlikely given if that were true, we would expect a public response from Palo Alto to that effect? That isn’t a ploy that would work very long and the backlash and damaged reputation would be significant if that occurred.
- cddotdotslash 6y agoNo, not fabricated at all. I'm suggesting that they had to know that what they were doing would provoke a response from PAN. And as soon as it did, a nice "underdog" blog post was ready to go.
- different_sort 6y agoPrisma cloud (the cloud monitoring part) is not a great product. It lags pretty far behind cloud provider capabilities. I also got the email that orca probably sent to everyone in their CRM about this, and while I didn’t need any reason to think less of prisma, I now associate Orca as a competitor and probably an earlier call than palo alto for cloud.
- CameronNemo 6y agoWe are considering prisma cloud to monitor an on premise kubernetes deployment. Is there anything I should be concerned about or better options to consider?
- different_sort 6y agoI actually have never seen it's kubernetes security platform. If it's using RQL for that I would take that as a redflag that it won't support much customization or logic that would allow you to tailor it to your organization.
- dipslip 6y agoThe Kubernetes protection is derived from their Twistlock acquisition which is really good (just wish they’d get some SAST stuff in there). Not tied to RQL (but can be queried with it for some information)
- rasz 6y ago>Enter your email once and get access to all videos on our site Are you trying to sell me access to a comparison trying to sell me on your product? Im confused and amused.
- mtnGoat 6y agoGee, big tech using high paid legal staff to attack and silence others unjustly. Seems like the usual situation to me. :(