4 ms·
(I’m in the anti-WAF camp) That does stand to improve your posture by giving you the ability to quickly apply duct tape to mitigate an active mild denial of ser
by CoffeeOnWrite 1y ago
(I’m in the anti-WAF camp) That does stand to improve your posture by giving you the ability to quickly apply duct tape to mitigate an active mild denial of service attack. It’s not utterly useless.
- elevation 1y agoDoesn't it also add latency to every request?
- tough 1y agoI think the main point is the WAF companies must have lobbied to get that into the checklist the main point is you need to pay a third party
- CoffeeOnWrite 1y agoYou can call your existing reverse proxy a WAF to check this checklist item. (Your point still stands, on the median companies may opt to purchase a WAF for various reasons.)
- zelphirkalt 1y agoOften it is just pushing responsibility.
- thunderfork 1y ago[dead]
- formerly_proven 1y agoSo does running McAfee on every POST body but some places really wanna do that regardless. (I at least hope the scanner isn't running in the kernel for this one).
- jrockway 1y agoYeah, we were asked to do this at my last job by some sort of security review. This one doesn't bother me as much. "Display 'network error' whenever a user uploads a file containing 'SELECT *'" is a bad user experience. "Some files in this repository have been flagged as containing a virus and are not visible in the web interface until allowed by an administrator," is OK with me, though.
- swyx 1y agosure but how much? 3-10ms is fine for the fast protection when shit hits the fan.
- krferriter 1y agoDenial of service prevention and throttling of heavy users is a fine use, searching for a list of certain byte strings inside input fields and denying requests that contain them isn't.