6 ms·
I work in application/product security and have managed WAFs for multi-billion dollar companies for many many years. Move DNS to Cloudflare and put a few WAF r
by 1B05H1N 3y ago
I work in application/product security and have managed WAFs for multi-billion dollar companies for many many years.
Move DNS to Cloudflare and put a few WAF rules on your site (managed challenge if bot score less than 2 / attack score == x). I doubt you'll even pay anything, and it will resolve a lot of your problems. Just test it before moving it to production please (maybe setup a test domain). Remember, a WAF is not an end-all be all, it's more of a band-aid. If you app isn't hardened to handle attacks, no amount of advanced WAF/bot protection will save it.
Message/email me if you need help.
- 93n 3y agoSelfhoster here. I use mutual TLS rules with CloudFlare's WAF to filter out everyone but my known-good callers. Works great. Since the only folks with access are my family, it was pretty easy to setup as well (everyone gets a unique cert that I can revoke if need be).
- asabla 3y agoUsually I only manage internal facing applications these days, which makes the attack surface greatly reduced compare to public ones. But since you seem to have a lot of knowledge in this area. Have you manage solutions which also includes infrastructure in Azure combined with Cloudflare? And if so, any suggestions on things people usually miss? except for the usual stuff of OWASP and what not
- CharlesW 3y agoI was unfamiliar with this, so for anyone who's in a similar position: https://blog.cloudflare.com/waf-for-everyone/ https://blog.cloudflare.com/waf-for-everyone/ The Free Managed Ruleset appears to be deployed by default, and Cloudflare keeps a changelog here: https://developers.cloudflare.com/waf/change-log https://developers.cloudflare.com/waf/change-log
- 418tpot 3y ago[flagged]
- solumunus 3y ago> Hacker news is so funny, they complain about the amount of power we've allowed Google, Amazon, and Microsoft to have, and then go right around and recommend putting everything behind Cloudflare. It’s almost as if those saying contradictory things are actually different people despite being on the same website. But it can’t be that, surely? Truly a perplexing phenomenon that I hope someone can one day explain.
- 418tpot 3y agoFair, although I know quite a few people that hold both of these opinions simultaneously because I've met them in person. It's only after I point out their hypocrisy do they even realize what a danger Cloudflare poses to the free and open internet. I suspect it's because hating on Google is in vogue, and so is recommending Cloudflare.
- jopsen 3y agoGiven how Cloudflare works I imagine that there are alternative services offering the same thing. Probably not as cheap. AWS can put a WAF and CDN infront of your site too. And migrating from one service to another isn't much more work than moving DNS records. Just saying, it's not the same level of vendor lockin as using dynamodb or whatever.
- BLKNSLVR 3y agoI'm going to try to provide / justify my potentially hypocritical viewpoint: I use Cloudflare (free tier) in front of the very few and almost entirely unused websites that I run. I believe that the service they provide is useful for protecting the IP addresses of the servers on which the content is hosted, whilst also providing some amount of protection from malicious traffic. I also agree that centralisation of services is a big problem for the future of the internet. My position is that, whilst there seem to be increasing voices / examples of Cloudflare's (potential in) acting against the nebulous notion of "spirit of the internet", for me they certainly haven't reached the "evil" stage. I'm also of the understanding that it's Cloudflare customers that choose to block access from Tor or VPS IP address ranges and / or add Captcha's or other bothersome verification. True Cloudflare enable it and make it possible, but the administrators of the website that you're trying to visit have made the choice to make it more difficult for you to access their content; not Cloudflare themselves. I would prefer there to be similar-scale alternatives to Cloudflare as a kind of a middle-ground decentralisation of centralisation. I'm sure there are alternatives, but I'm not yet motivated enough to even consider starting the research process. If Cloudflare start selling visitor analytics to data brokers, however, very fast goodbye.
- ozim 3y agoPutting WAF on app and calling it a day is indeed putting lipstick on a pig. I can imagine that might be needed if some company for some reason has to run some not really up to date stuff but yeah it is just a bandaid.
- cloudking 3y agoThis works well for standard WordPress sites, throw in GuardGiant and Sucuri plugins for extra layers.