← Front page

Risky Business · Friday, August 14, 2026

Patching Insufficient for Internet-Exposed Services: Knockknock as Solution

Patrick Gray asserts that organizations running services like Citrix or using firewalls from Fortinet and Palo Alto on the internet edge cannot outrun attackers by relying solely on patching. He suggests that a mitigation like Knockknock is necessary to extend the usable life of these assets by hiding them and reducing attack surface.

personPatrick GraycompanyCitrixcompanyFortinetcompanyPalo AltocompanyKnockknock

The tape

3 quotes
So stuff like if you're running stuff like Citrix, if you're running Fortinet on the edge. You are not going to be able to outrun attackers with patching, right? That is just not going to happen.
Patrick Gray
So you've got a couple of options. You can apply a mitigation like Knockknock, which is going to extend the life you get out of that stuff. But there you options. Patching, it ain't going to do it.
Patrick Gray
So again, patching isn't going to work.
Patrick Gray
Heard on Risky Business — “Soap Box: Zero Trust(ish) Networks, published Friday, August 14, 2026. Heardvine summarizes and quotes with attribution and timestamps, and links to the original everywhere.
Transcribed via Gemini audio transcription · $0.04
Patching Insufficient for Internet-Exposed Services: Knockknock as Solution — Heardvine