Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In general, I'm not a huge fan of using WAFs to protect web applications -- I've spent too much of my career bypassing WAFs to have a lot of confidence in them. That said, using a WAF can hugely improve application security visibility, if not increase actual resilience.

The AWS WAF is, presumably, going to give application developers and owners significantly more insight into whether their apps are getting attacked. Congratulations to the Amazon team for shipping something that has the potential to make a really big difference.

At this point, my only question is why Amazon didn't give it a strange name (like most of the other AWS products)!



my only question is why Amazon didn't give it a strange name (like most of the other AWS products)!

Maybe they decided that "WAF" was sufficiently ambiguous. My first guess was s/firewall/framework/.


I'd have given them major kudos if they'd called it Web Traffic Firewall instead.


The first alternative name which came to my mind was "API Condom", but I like your idea more.


Amazon WTF


From the defensive side, WAFs can be quite helpful for alerting. It's detection, typically not prevention (against a dedicated attacker at least), but it helps.


If your application is on the web, it is being attacked. There's no whether about it.


I've seen attack traffic on machines within 30 minutes of adding an IP address to a domains DNS records. Before the web server was even up to record the we attempts, it was being hit with ssh brute force attempts.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: