3 ms·
Can't you do a captcha with the WAF? I'm pretty sure that's an option on AWS
by Monotoko 5y ago
Can't you do a captcha with the WAF? I'm pretty sure that's an option on AWS
- miyuru 5y agothe attack was to an api endpoint. which is queried via xhr on the main app. adding captcha to it would break the app to all users. the developers are now working on adding captcha at the application level and also signing the api endpoints.
- dragonwriter 5y ago> Can't you do a captcha with the WAF? I'm pretty sure that's an option on AWS You can. I know because our information security office did it to all of our web endpoints. Which are mostly API endpoints. Without telling anyone involved with individual apps, before or even, until specific complaints got to them, after doing it.
- exikyut 5y ago*Large rueful sigh* I feel your pain. It's stuff like that that just makes you know, they not only have no idea what they're doing, the level of agency and access they have mean it's just a question of when they finally accidentally something big on fire one day - and whether you'll be able to make it out unscathed with eg just some lost sleep. Would probably make a good story for http://old.reddit.com/r/talesfromtechsupport http://old.reddit.com/r/talesfromtechsupport, as you're probably already aware. If you feel like (and can stand) writing it (heh).