[HN Gopher] Detection Is Not Protection: What WAF Detection Mode...
       ___________________________________________________________________
        
       Detection Is Not Protection: What WAF Detection Mode Does (and
       Doesn't)
        
       Author : shadowAuror
       Score  : 5 points
       Date   : 2026-03-08 21:56 UTC (1 hours ago)
        
 (HTM) web link (blog.ebbypeter.com)
 (TXT) w3m dump (blog.ebbypeter.com)
        
       | PunchyHamster wrote:
       | Unless you're hosting array of common apps (like wordpress), WAF
       | is waste of time of everyone involved and the time would be
       | better spent actually auditing the application you wrote rather
       | than fighting with false positives.
       | 
       | The industry sold the idea to the gullible that they can make a
       | bunch of arbitrary pattern matching rules that just make any app
       | more secure
        
       | tl2do wrote:
       | AWS forces an explicit default choice--Allow or Block. Azure
       | defaults to passive "Detection," requiring a manual switch to
       | "Prevention." An AWS engineer, used to making this conscious
       | decision, might miss that Azure requires a separate, critical
       | step to actually turn protection on.
        
       ___________________________________________________________________
       (page generated 2026-03-08 23:00 UTC)