Your site talks of BunkerWeb PRO, which is, by the sound of it, not open source. But I have no idea what is actually different about it: https://panel.bunkerweb.io/knowledgebase/105/What-is-BunkerW... flatly doesn’t answer the question: “additional features and services responding to professional needs” is impressively vague.
Features with a crown icon are PRO, you will find full list of free and PRO features here : https://docs.bunkerweb.io/latest/features/
Show HN: BunkerWeb – the open-source and cloud-native WAF
21–30 of 32 posts
Re: Show HN: BunkerWeb – the open-source and cloud-native WAF
#22I'm still strongly suspecting this whole WAF thing is mostly complete bullshit intended for projects doing security works mostly from spreadsheets. Could someone with a proper background in security confirm or invalidate my suspicion ?
I'd generally confirm that suspicion: https://www.macchaffee.com/blog/2023/wafs/ WAFs have a few valid uses in my opinion: "virtual patching" and the ability to create custom rules such as blocking/challenging/rate limiting obviously bad traffic. But the giant rulesets are actively harmful IMO. "Defense in depth" is not a valid justification for doing something actively harmful to both your users and the time budget…
Re: Show HN: BunkerWeb – the open-source and cloud-native WAF
#23I'm still strongly suspecting this whole WAF thing is mostly complete bullshit intended for projects doing security works mostly from spreadsheets. Could someone with a proper background in security confirm or invalidate my suspicion ?
I'd generally confirm that suspicion: https://www.macchaffee.com/blog/2023/wafs/ WAFs have a few valid uses in my opinion: "virtual patching" and the ability to create custom rules such as blocking/challenging/rate limiting obviously bad traffic. But the giant rulesets are actively harmful IMO. "Defense in depth" is not a valid justification for doing something actively harmful to both your users and the time budget…
Re: Show HN: BunkerWeb – the open-source and cloud-native WAF
#24I'm still strongly suspecting this whole WAF thing is mostly complete bullshit intended for projects doing security works mostly from spreadsheets. Could someone with a proper background in security confirm or invalidate my suspicion ?
Re: Show HN: BunkerWeb – the open-source and cloud-native WAF
#25I'm still strongly suspecting this whole WAF thing is mostly complete bullshit intended for projects doing security works mostly from spreadsheets. Could someone with a proper background in security confirm or invalidate my suspicion ?
Re: Show HN: BunkerWeb – the open-source and cloud-native WAF
#26Re: Show HN: BunkerWeb – the open-source and cloud-native WAF
#27I'm still strongly suspecting this whole WAF thing is mostly complete bullshit intended for projects doing security works mostly from spreadsheets. Could someone with a proper background in security confirm or invalidate my suspicion ?
Most bad actors are looking for easy targets and will move on when seeing minimal defenses. If we want to continue enjoying an open and accessible internet where any client that speaks the protocol can connect, then WAFs are an integral part of maintaining that public service.
Re: Show HN: BunkerWeb – the open-source and cloud-native WAF
#28Re: Show HN: BunkerWeb – the open-source and cloud-native WAF
#29What % of cloudflare's protection can this provide? I've been looking at bunkerweb + anubis as alternative to cloudflare tunnel (im actually not sure if this provides WAF)
While this offers many of the same technical capabilities as Cloudflare, a lot of Cloudflare's value is in having high-level, aggregate insight into threats.
Re: Show HN: BunkerWeb – the open-source and cloud-native WAF
#30I'm still strongly suspecting this whole WAF thing is mostly complete bullshit intended for projects doing security works mostly from spreadsheets. Could someone with a proper background in security confirm or invalidate my suspicion ?
Testing and deploying patches takes time probably you cannot just update 10 apps at once with single click.
Deploying WAF rule should cover that.