FortiBleed, Fortinet, and the Firewall That Became the Failure Noel Bradford unleashes a withering critique of Fortinet following the FortiBleed vulnerability’s impact on British embassies, the Foreign Office, and the British Council. This is not a balanced analysis; it is a controlled explosion aimed at a vendor that keeps appearing in credential exposure stories despite its market dominance and recurring revenue model. Bradford demands answers: why does one of the world’s largest security companies repeatedly feature in edge device exploitation headlines? Why are customers paying annual licences for products that become the risk conversation? And why, in an era when frontier AI models like Anthropic’s Claude Mythos Preview are being deployed to hunt vulnerabilities in critical software, are we still watching firewalls, the devices sold as the safe bit, turn into national security incidents? He dismantles the familiar cycle of advisory, exploitation, and carefully worded apology, and asks whether recurring revenue comes with recurring responsibility or just recurring anxiety. Public bodies, MSPs, and the industry’s talent for turning failure into beige process language all come under fire. This is a rant, a reckoning, and a refusal to pretend this is fine. Chapters Cold Open Noel opens with cold fury, warning listeners this is a rant. FortiBleed has hit British embassies, the Foreign Office, and the British Council. He refuses to deliver the vendor-friendly version or pretend the complexity excuses the pattern. Fortinet’s ubiquity in critical infrastructure makes its repeated appearance in exploitation headlines unforgivable.The Safe Bit The firewall was sold as the safe bit, the thing with the green dashboard and the procurement-friendly quote. It turns out it was just another internet-exposed computer holding keys and terminating VPN sessions. Noel is tired of the cycle: advisory, exploitation, emergency guidance, carefully worded statement, patch advice, shuffle on.The Fortinet Question The question is not just whether customers patched. Fortinet sells security and confidence. Why does one of the largest security vendors on the planet keep ending up in headlines around exploited edge devices, credential exposure, and large scale customer panic? This is a reputational and governance problem.The Price Of Being Big All vendors have vulnerabilities, but frequency, pattern, and blast radius matter. If your kit is everywhere, your mistakes are everywhere. You do not get giant market share and giant recurring revenue, then act wounded when people expect giant levels of assurance. You wanted the market; now carry the weight.Hard Coded Credentials Noel drags the hard coded credentials issue back into the room, referencing Fortinet’s PSIRT entry for dummy testing data in FortiManager and FortiAnalyzer. Hard coded credentials in security software is a phrase that should make eyebrows leave faces. The optics are appalling when your commercial promise is trust.Mythos And Glasswing Anthropic has deployed Claude Mythos Preview, a frontier AI model, to find and fix vulnerabilities in critical software as part of Project Glasswing. Firewalls are critical software. Noel demands to know whether Fortinet has access to Mythos or an equivalent, because edge security appliances should be attacked internally before criminals get the pleasure.The Licence Model Fortinet’s business model is wrapped in recurring licences. Customers pay annually because threats move daily. But recurring revenue must come with recurring responsibility. If you charge every year, your product security has to move every day. Otherwise, what are customers renewing: protection, or access to the next apology?Subscription To Anxiety Customers were sold maturity, scale, and expertise. FortiBleed makes it feel upside down. The firewall became the risk conversation. The security vendor became the source of anxiety. The recurring licence starts to look like a subscription to anxiety with rack ears.Public Sector Trust British embassies, the British Council, and Foreign Office credentials are reportedly in the mix. People give data to public bodies because they have to. They do not get to inspect the firewall first. They just get the email afterwards, the one about an abundance of caution. Caution is never abundant before the breach.MSPs Do Not Get To Hide If you sold this kit, you own the conversation. If you manage it, you produce evidence. Vanishing behind a ticket note saying awaiting customer instruction is cowardice with a service desk reference. The edge is where the attack starts. If your definition of managed is occasionally aware, stop using the word managed.Why I Am Angry Noel is angry because the same story keeps coming back. A company with Fortinet’s scale should be held to a brutal standard. Customers pay recurring money for security and still wonder whether the security product is the problem. Hard coded credentials should ...
続きを読む
一部表示