Live data from Hacker News

Show HN: BunkerWeb – The Open-Source Web Application Firewall (WAF)

github.com

21–30 of 31 posts

Re: Show HN: BunkerWeb – The Open-Source Web Application Firewall (WAF)

#21
post #12

"live threatmap of live cyber attacks blocked by BunkerWeb instances all around the world" So this sketchy looking thing is also equipped with telemetry that phones home all the time? No thanks.

A WAF looks sketchy? OSINT is sketchy?

Re: Show HN: BunkerWeb – The Open-Source Web Application Firewall (WAF)

#22
post #12

"live threatmap of live cyber attacks blocked by BunkerWeb instances all around the world" So this sketchy looking thing is also equipped with telemetry that phones home all the time? No thanks.

A WAF looks sketchy? OSINT is sketchy?

An open source WAF at that.

Re: Show HN: BunkerWeb – The Open-Source Web Application Firewall (WAF)

#23
post #12

"live threatmap of live cyber attacks blocked by BunkerWeb instances all around the world" So this sketchy looking thing is also equipped with telemetry that phones home all the time? No thanks.

Enterprises pay a shitload of cash for that functionality of commercial WAF systems. Some allow that at a low let cost of you send your own data, and more expensive if you don't.

Re: Show HN: BunkerWeb – The Open-Source Web Application Firewall (WAF)

#24
I'll have to check it out! The popular option for homelab or other indie scale is to just use the cloudflare's free-tier setup, which includes WAF, but I see a privacy hole where cloudflare needs to see your unencrypted HTTP traffic so that they can apply their WAF rules.

I've also been checking out CrowdSec. I appreciate it's modular architecture but it definitely deviates away from the folks that just wants to expose an HTTP service and get on with their lives. I've enjoyed the Caddy server for this reason, but yeah, not as secure-as-default when it comes to attacks a WAF would mitigate.

Re: Show HN: BunkerWeb – The Open-Source Web Application Firewall (WAF)

#26
For Fucks Sake offering "dark mode" is the 3rd or 4th highlight in the promo video.

You could dark mode application in X Windows way back in the day with just a bit of configuration.

This may be two style sheets you can swap between or whatever. It is not impressive.

What about "Blue letters available" ohhhh .

I keep seeing apps being update and the major change being "dark mode now available".

Re: Show HN: BunkerWeb – The Open-Source Web Application Firewall (WAF)

#28

I'll have to check it out! The popular option for homelab or other indie scale is to just use the cloudflare's free-tier setup, which includes WAF, but I see a privacy hole where cloudflare needs to see your unencrypted HTTP traffic so that they can apply their WAF rules. I've also been checking out CrowdSec. I appreciate it's modular architecture but it definitely deviates away from the folks that just wants to expo…

Check out SafeLine.

Re: Show HN: BunkerWeb – The Open-Source Web Application Firewall (WAF)

#29
I recently joined a new company, and one of my first tasks is to secure a simple web API using a WAF. I’d like to explore some free and open-source options to help our office avoid licensing headaches. Do you have any recommendations?

Re: Show HN: BunkerWeb – The Open-Source Web Application Firewall (WAF)

#30

For Fucks Sake offering "dark mode" is the 3rd or 4th highlight in the promo video. You could dark mode application in X Windows way back in the day with just a bit of configuration. This may be two style sheets you can swap between or whatever. It is not impressive. What about "Blue letters available" ohhhh . I keep seeing apps being update and the major change being "dark mode now available".

I agree it might not be worth promoting as a main feature at all. But from experience, there are users that will be very vocal about it and request a dark mode.
Post reply on HN