3 ms·
I know people will say "defense in depth", but it really seems more like security theater to me. It only catches some basic (but admittedly historically common
by latch 5y ago
I know people will say "defense in depth", but it really seems more like security theater to me. It only catches some basic (but admittedly historically common) mistakes. The problem with most WAFs is that they tend to have false positives, which can block/trouble legitimate users.
- stefs 5y agoe.g. the case of the man named "Null" who's unable to access a lot of online services.
- arp242 5y agoI once had a password with a " in it and I could never log in. It took me ages to discover that was because of the " and their "protection". This was for a large company that really ought to know better. I do think it can add value, especially when done right, especially considering the context of 2005 when it was added and when these sort of things were horrendously common. These days, I probably wouldn't bother so much, although it would depend on the context. If I were to allow random people to host WordPress or some such I'd probably add something like this, even today. Not because WordPress is bad, but because you never know what random plugins people are going to install, and the quality of that is a lot more ... variable ... than WordPress itself, and your users having their entire database leaked/dropped/overwritten also sucks for everyone.