<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WildFire - Confidentiality Concerns? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36011#M26463</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Networkadmin&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PAN firewall will not send the actual file to the Wildfire cloud, instead&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; ,&lt;/SPAN&gt; it will calculate the MD5 hash of the file and send to wildfire to analysis. Hence, there is no risk factor from "confidentiality" point of view. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more detail info, please refer &lt;A href="https://live.paloaltonetworks.com/docs/DOC-6589"&gt;WildFire Administrator's Guide 6.0 (English)&lt;/A&gt;&amp;nbsp; ---- Page No-6 (How Does WildFire Work?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 Jun 2014 16:16:56 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-06-19T16:16:56Z</dc:date>
    <item>
      <title>WildFire - Confidentiality Concerns?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36010#M26462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm interested in 6.0 mainly for the Wildfire improvements as it can now process PDF and Office documents.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've read the PDF on how Palo Alto handle file security, I guess I'm interested in peoples "comfort levels" at submitting documents which are potentially confidential in nature to something like WildFire.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At some point it's basically a judgement call - love to know which way you've called it and why &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jun 2014 16:00:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36010#M26462</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2014-06-19T16:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: WildFire - Confidentiality Concerns?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36011#M26463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Networkadmin&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PAN firewall will not send the actual file to the Wildfire cloud, instead&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; ,&lt;/SPAN&gt; it will calculate the MD5 hash of the file and send to wildfire to analysis. Hence, there is no risk factor from "confidentiality" point of view. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more detail info, please refer &lt;A href="https://live.paloaltonetworks.com/docs/DOC-6589"&gt;WildFire Administrator's Guide 6.0 (English)&lt;/A&gt;&amp;nbsp; ---- Page No-6 (How Does WildFire Work?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jun 2014 16:16:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36011#M26463</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-06-19T16:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: WildFire - Confidentiality Concerns?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36012#M26464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But surely as with executables if it hasn't been seen it will upload it to check?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jun 2014 16:22:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36012#M26464</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2014-06-19T16:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: WildFire - Confidentiality Concerns?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36013#M26465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well it has to upload it to test it if the checksum returns unknown surely?&amp;nbsp; That's how it works with executables so I'm assuming the process would be the same with Office docs and PDFs else how can it test stuff it hasn't seen?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jun 2014 16:33:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36013#M26465</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2014-06-19T16:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: WildFire - Confidentiality Concerns?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36014#M26466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is not correct.&amp;nbsp; The file &lt;STRONG style="text-decoration: underline;"&gt;will&lt;/STRONG&gt; be uploaded to the WildFire service if the MD5/SHA256 hash has not been previously analyzed.&amp;nbsp; The process is the same for all supported file types.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jun 2014 16:35:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36014#M26466</guid>
      <dc:creator>kfindlen</dc:creator>
      <dc:date>2014-06-19T16:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: WildFire - Confidentiality Concerns?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36015#M26467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;Whenever a file is transferred over a session that matches the security rule, the firewall &lt;/P&gt;
&lt;P&gt;performs a file hash check with WildFire to see if the file has been previously analyzed. If the file is new, it is &lt;/P&gt;
&lt;P&gt;forwarded for analyses, even if it is contained within a ZIP file or over compressed HTTP&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;From the WF Admin Guide. The file will be transferred to the WF Cloud&amp;nbsp; if it has not seen before by WF.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jun 2014 16:35:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36015#M26467</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2014-06-19T16:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: WildFire - Confidentiality Concerns?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36016#M26468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The hash is used to determine whether or not the entire file needs to be sent for analysis.&amp;nbsp; If the WildFire cloud already has a copy of the file - other firewalls don't need to send additional copies, consuming bandwidth and processing power.&amp;nbsp; However, if the WildFire cloud has not yet seen the file, then your firewall (if configured) will forward the entire file to the cloud for full analysis/detonation.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For customers concerned with security/privacy, here are some of the options:&lt;/P&gt;&lt;P&gt; - Read Palo Alto Networks privacy and security statement concerning file retention &amp;amp; security measures taken in the WildFire Cloud&lt;/P&gt;&lt;P&gt; - Limit the files to be analyzed, ie: internally generated PDF files going out to the Internet do not get analyzed, but any file coming from the Internet into the environment are sent to WildFire. &lt;/P&gt;&lt;P&gt; - Use the WF-500 as a "private WildFire cloud"&amp;nbsp; If you have a WF-500, all of the analysis occurs in your own environment.&amp;nbsp; Further, you have the option of sharing nothing with Palo Alto Networks, or only the files with a "malicious" verdict.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jun 2014 16:41:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36016#M26468</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2014-06-19T16:41:18Z</dc:date>
    </item>
    <item>
      <title>Re: WildFire - Confidentiality Concerns?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36017#M26469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I've certainly read that guide, it wasn't so much a black and white "What do Palo Alto do?" question, rather that I wanted to check peoples comfort levels/paranoia about what is submitted.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jun 2014 16:48:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36017#M26469</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2014-06-19T16:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: WildFire - Confidentiality Concerns?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36018#M26470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm working in the National Cancer Institute, and we must, by law, prevent the transfer any file with "protected health information" in it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since we can't know beforehand which file might possibly contain protected health information, we have to prohibit the transfer of any file to the WildFire cloud.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jun 2014 18:00:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36018#M26470</guid>
      <dc:creator>Rick_Rutherford</dc:creator>
      <dc:date>2014-06-19T18:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: WildFire - Confidentiality Concerns?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36019#M26471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Being subject to restrictions in both PCI and PHI handling, we also are looking to test deploy of the internal WF-500.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basic Wildfire shipping of executable is no issue.&amp;nbsp; But the document formats pose too much of a compliance risk to automatically ship off-site.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jun 2014 22:17:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36019#M26471</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-06-19T22:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: WildFire - Confidentiality Concerns?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36020#M26472</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We would normally be more interested in the office and pdf documents coming down from public web sites or being sent inbound via email.&amp;nbsp; In both cases there should not be confidential info. We have secure file transfer technologies for the secure transmission of documents so anyone sending confidential info inbound via standard email is in violation of policy. You could selectively not forward those potentially sensitive documents if the communication was internal (and crossing a firewall boundry). The other option is the WF-500 as mentioned above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2014 13:14:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-confidentiality-concerns/m-p/36020#M26472</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2014-06-20T13:14:25Z</dc:date>
    </item>
  </channel>
</rss>

