3 ms·
Is a security solution worthless if it can't stop a dedicated attacker? A lot of WAF rules are blocking probes from off-the-shelf vulnerability scanners.
by eli 1y ago
Is a security solution worthless if it can't stop a dedicated attacker? A lot of WAF rules are blocking probes from off-the-shelf vulnerability scanners.
- da_chicken 1y ago"It's technically better than nothing," is kind of a bizarre metric. It's like not allowing the filesystem to use the word "virus" in a file name. Yes, it technically protects against some viruses, but it's really not very difficult to avoid while being a significant problem to a fair number of users with a legitimate use case. It's not that it's useless. It's that it's stupid.
- eli 1y agoDo you lock your front door?
- da_chicken 1y agoDo you brace yours with a bar?
- eli 1y agoNo, but even a steel bar would only slow down a determined thief...so I guess it's worthless?
- ndsipa_pomu 1y agoIt's merely security theater. It reminds me of when airports started scanning people's shoes because an attacker had used a shoe bomb. Yes, that'll stop an attacker trying a shoe bomb again, but it disadvantages every traveller and attackers know to put explosives elsewhere.
- geoffpado 1y ago“attacker had used a shoe bomb” It’s even dumber than that. An attacker tried and failed to use a shoe bomb, and yet his failure has caused untold hours of useless delay for over 13 years now.
- kevin_thibedeau 1y agoNow you have to buy your liberty with pre-check.
- eli 1y agoMost ransomware attacks are opportunistic. They scan basically the whole internet for vulnerabilities and attack from there. It's usually not a skilled attacker targeting a specific company. Ransomware is a huge and growing problem. Very different than airline security, where attacks are extremely uncommon. If planes were constantly getting blown up, and if a majority of those attacks started with a shoe bomb, then checking everyone's shoes would seem a lot more reasonable, no?
- richardwhiuk 1y agoEvery security solution can only stop a certain fraction of attacks.
- kevincox 1y agoIMHO the primary value for WAFs is for quickly blocking known vulnerabilities with specific rules to mitigate vulnerabilities while they are being properly patched. Ideally the WAF knows what software is behind it (example WordPress, Java app, ...) and can apply filters that may be relevant. Anything else is just a fuzzy bug injector that will only stop the simplest scanners and script kiddies if you are lucky.