5 ms·
WAFs are security theater. False positives and false sense of security. People say "security in depths", but WAFs add nothing that don't 100% _have_ to be miti
by latch 5y ago
WAFs are security theater. False positives and false sense of security.
People say "security in depths", but WAFs add nothing that don't 100% _have_ to be mitigated down the stack - this 8K limit is just another part of the joke.
- idorosen 5y agoSome web application firewalls have better telemetry, monitoring, notification, etc. than the services behind them, especially for unsophisticated attacks. Also, any attacker filtered is one less connection wasting resources on the hosts running your actual services, leaving more CPU and memory to handle legitimate requests on application servers. None of them defend against everything, and there is an important nugget in your post: “defense in depth.” You should also filter requests that make it through the WAF. But, getting rid of even 90% of bogus requests before they hit your app servers seems worthwhile.
- GauntletWizard 5y agoThose are all nice to have, but that's called a load balancer. It should also have rate limiting and DOS protection, and I use the AWS WAF for those things, and don't really care that they're in a separate feature and that that feature is misnamed. For every defense in depth, there's an org that's put up a WAF rule in front of an unpatched application and called it good, only yo be owned days later. False sense of security is the thing to stress here, because there is no depth.
- withinboredom 5y agoI mean, most of the cloud is theater that your managers want to see. Setting up queues, distributed storage (s3 compatible), etc is incredibly easy these days. There’s very little reason for using the cloud, unless you really need the elasticity and I can only imagine a very few verticals that actually need it. Everyone else just “thinks” they need it, the reality is there elasticity requirements are on the order of 5%-10% of a baseline, which they’d save far more with bare metal all the way. Don’t get me wrong, serverless is pretty amazing until you get to a certain scale. The cloud really has that going for it.
- samwillis 5y agoHard disagree on this, they certainly shouldn't be your only defence but I think for the vast majority of sites they are essential. Most site on the internet are either run by a tiny team with no dedicated security expert or no tech team at all (someone asked a friend/freelancer to put up a Wordpress site). They aren’t applying security patches and subscribing to the developer mailing lists. A WAF service (like CloudFlare) ensures that older, unpatched, infrastructure is protected. Yes, they should be patching their deployment, but try asking a small business to pay for their web guy to spend a few fours a month ensuring everything is secure. Not going to happen. From my perspective as someone with a good understanding of web security. I run a WAF service on my sites so that if there is a zero day on part of my stack We are protected immediately before we have time to patch the component, which I will do. That is invaluable to me and my business. Finally developers do make mistakes and accidentally introduce vulnerabilities. A WAF helps to ensure against that, although you should still be auditing your code.
- latch 5y ago> A WAF service (like CloudFlare) ensures that older, unpatched, infrastructure is protected It ensures that they're protected against a trivial and fairly outdated set of threats. You might say that's better than nothing, but questionable protection leading to a sense of security is more dangerous than having nothing and knowing it (also, false positives). > We are protected immediately Look at the recent log4j vulnerabilities. Hosted WAFs didn't "immediately" address the issue (though they were fairly quick). However, to the best of my knowledge they were unable to fully mitigate the threat. For example, if you look at CloudFlare's wording on rule 2c5413e155db4365befe0df160ba67d7: > In addition to the above rules we have also released a fourth rule that will protect against a much wider range of attacks at the cost of a higher false positive rate. For that reason we have made it available but not set it to BLOCK by default It's clear that, by default, their updated rules didn't fully mitigate the issue. Also, it IS NOT clear, whether the extra rule did fully mitigate the issue. Fundamentally, having a WAF in the face of log4j did nothing for you. You still have to patch everything, you still had to try and figure out if you'd been compromised, and you still had to update/alert your clients/customers.
- 5y ago
- xiwenc 5y agoWAF’s intention is to catch common attacks. I was also skeptical about it until I saw Azure application gateway WAF’s default policies to fend off log4j attacks. My take is now to configure WAF at a generic level with minimal impact on application functionalities. And yes, the value of WAF’s is overrated. Cause with proper development guidelines like using ORM instead of writing plain SQL queries, you can throw away half of the default policies which revolve around SQL injections. For large organizations, having a WAF does add some value. With security it’s all about adding layers of protection wherever possible.
- MattPalmer1086 5y agoYou hardly need to use ORM! Just use prepared statements and bind your parameters and no SQL injection is possible. And faster than plain SQL or using an ORM!
- kevincox 5y agoA WAF is to buy you time to fix your application. It isn't a bulletproof situation. For example if you discover a vulnerability in your code that is being exploited you can push a WAF rule to block the easiest ways to trigger it. Or if you use a common library like log4j you can rely on rulesets that are updated for you. Likely before your smaller team has time to react. In that time you should be rushing to fix your application or update dependencies and deploy the new version.
- icecap12 5y agoEvery time someone posts about a WAF bypass on HN, someone like you comes along and talks about how WAFs are nothing but security theatre. Simply not true. Are they perfect? Absolutely not. I'll simply repost one of my previous comments on this topic: You deploy a WAF as part of a defense in depth strategy, with one of the best use-cases being situations where you have legacy web systems that nobody is maintaining. Additionally, you can get TLS upscaling, easy HTTP rewrite capabilities, DDoS protection, and other granular controls with some SaaS offerings. So while it's true that a WAF won't stop a determined attacker, there are certainly benefits to operating them, particularly in large enterprise environments.
- malaya_zemlya 5y ago99% of malicious traffic, in my experience, comes from random untargeted vulnerability scans. WAFs absolutely do help with these, if only by lowering load on actual servers.
- bradknowles 5y agoThink of a WAF like the thinnest possible veil over your code. You wouldn't go out into public wearing the thinnest possible veil as your only piece of clothing, would you? So make sure you bake in security through your code, and then when you are done, you can afford to make a decision about whether you need to put the thinnest possible veil over that.