Hacker News new | past | comments | ask | show | jobs | submit login

WAF has it's purpose but it's clearly not a silver bullet. Nothing is.



WAF is brittle and breaks more than it fixes IMO. It's just regex against URL's in 99% of cases. If you think you need one, you need to fix the app code, there will be more vulnerabilities it doesn't block


WAF provides a lot of other things, such as IP based filtering.


If it's so easily circumvented I wonder if it's worth the costs.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: