flâneur — a map of the web's best reading

Edition 14: To WAF or not to WAF - by Sandesh Mysore Anand

boringappsec.substack.com · 1,543 words · saved by 1 readers

First, a confession: For the longest time, I have been biased against WAFs. Most WAF tool sales pitches are too good to be true and often feels like NetSec folks trying to solve AppSec issues, without understanding AppSec well enough. Unsurprisingly, there’s more nuance than that. A few days ago, On a Twitter space with Chris Folini and others, his answer to a question of mine (34m mark) got me thinking. It’s clear that WAFs work well against some kind of attacks and can only respond in a limited set of ways (block or slow down traffic), but it’s unclear what those attacks are and what types of responses they work well against. It maybe useful to develop a hypothesis which helps us determine when WAFs can be useful. WAFs can be used as a part of the defense strategy only when two conditions are met: (1) The cost of fixing the defect in the target software is prohibitively more expensive than blocking attack traffic and (2) the organization can tolerate a percentage of legitimate traffi

The Boring AppSec Newsletter Edition 14: To WAF or not to WAF Effectiveness of WAFs are a hotly debated subject in AppSec circles. This editions tries to bring a structure to that discussion. Sandesh Mysore Anand Jan 02, 2022 8 Share Shakespeare answering an important question: To WAF or not to WAF. Image credit: iofoto Subscribe First, a confession: For the longest time, I have been biased against WAFs. Most WAF tool sales pitches are too good to be true and often feels like NetSec folks trying to solve AppSec issues, without understanding AppSec well enough. Unsurprisingly, there’s more nuan

Explore this link on the map →

related reading