logoalt Hacker News

pvglast Tuesday at 6:59 PM3 repliesview on HN

This is not CF WAF's first rodeo https://news.ycombinator.com/item?id=20421538

Cementing its track record as a product that mostly doesn't do anything except for occasionally break the internet here and there to keep things fun and interesting.


Replies

lynnesbianlast Wednesday at 12:37 AM

> a product that mostly doesn't do anything except for occasionally break the internet

I wouldn't say that. The postmortem you referred to links to another CloudFlare blog post - one about a pretty serious RCE vuln in Microsoft SharePoint that was blocked by their WAF: https://blog.cloudflare.com/stopping-cve-2019-0604/

show 1 reply
AdamJacobMullerlast Tuesday at 7:16 PM

I'm not sure why "WAF has false positives" makes it useless, nor would I say this is anywhere near the scale of "breaking the internet" and I'm not even fan of the concept of WAFs in general.

show 1 reply
calvinmorrisonlast Tuesday at 7:04 PM

we've used it to rescue some vintage appliances that are basically unsecurable.