[HN Gopher] Detection Is Not Protection: What WAF Detection Mode...
___________________________________________________________________
Detection Is Not Protection: What WAF Detection Mode Does (and
Doesn't)
Author : shadowAuror
Score : 5 points
Date : 2026-03-08 21:56 UTC (1 hours ago)
(HTM) web link (blog.ebbypeter.com)
(TXT) w3m dump (blog.ebbypeter.com)
| PunchyHamster wrote:
| Unless you're hosting array of common apps (like wordpress), WAF
| is waste of time of everyone involved and the time would be
| better spent actually auditing the application you wrote rather
| than fighting with false positives.
|
| The industry sold the idea to the gullible that they can make a
| bunch of arbitrary pattern matching rules that just make any app
| more secure
| tl2do wrote:
| AWS forces an explicit default choice--Allow or Block. Azure
| defaults to passive "Detection," requiring a manual switch to
| "Prevention." An AWS engineer, used to making this conscious
| decision, might miss that Azure requires a separate, critical
| step to actually turn protection on.
___________________________________________________________________
(page generated 2026-03-08 23:00 UTC)