Show HN: BunkerWeb – the open-source and cloud-native WAF
docs.bunkerweb.io
Show HN: BunkerWeb – the open-source and cloud-native WAF
1–10 of 32 posts
Re: Show HN: BunkerWeb – the open-source and cloud-native WAF
#2Neat to see another use case for NGNIX though!
Re: Show HN: BunkerWeb – the open-source and cloud-native WAF
#3Re: Show HN: BunkerWeb – the open-source and cloud-native WAF
#4Re: Show HN: BunkerWeb – the open-source and cloud-native WAF
#5Could someone with a proper background in security confirm or invalidate my suspicion ?
Re: Show HN: BunkerWeb – the open-source and cloud-native WAF
#6Re: Show HN: BunkerWeb – the open-source and cloud-native WAF
#7Re: Show HN: BunkerWeb – the open-source and cloud-native WAF
#8I'm still strongly suspecting this whole WAF thing is mostly complete bullshit intended for projects doing security works mostly from spreadsheets. Could someone with a proper background in security confirm or invalidate my suspicion ?
WAFs in and of themselves provide virtually zero security. They can block naive attacks -- catching the most obvious payloads -- and act as an early-warning signal that an attack may be underway (though the SNR on this is awful). But frankly, this is far less important in practice than the fact that it just makes things more difficult and annoying for attackers. Enough so that it can make a semi-attractive target into a no-go.
This is like defense-in-depth, but instead of layering protections in place so that the holes in the swiss cheese don't like up, you're making the cheese smell awful enough to ignore the juicy apple behind it.
If you're a valuable enough target, they're gonna go for the apple regardless of how bad the cheese is. ... And this analogy may have gotten away from me.
Re: Show HN: BunkerWeb – the open-source and cloud-native WAF
#9Re: Show HN: BunkerWeb – the open-source and cloud-native WAF
#10Is there a significant difference between this and nginx proxy manager?
In short, NPM doesn't do any of the stuff listed under Security Features here: https://docs.bunkerweb.io/latest/#security-features