Hacker News new | ask | show | jobs
by richbell 1355 days ago
> What classifies this as an "overzealous" act of network configuration? There may be a subjectively legitimate reason the user's network was configured this way.

Worked at a large FI.

Our corporate firewall used to block any website or payload that contained the word "hack". At one point, the security team decided to roll out a change that blocked all verbs except GET and POST without telling anyone. I could go on.

4 comments

And probably replies with a 200 and a blocked page.

What you tend to see is the web firewall is administered by someone who has only one duty (manage this firewall) and very narrow set of skills (certification in this appliance). They probably have a very shallow understanding of the http protocol.

And the nearby Burger Shack wondered why their online orders plummeted.
They were using PUT instead of POST for orders?
Wow, that's whack. I couldn't PUT up working in a place with such a hackneyed firewall limiting my OPTIONS so much, really raises my hackles. I'd HEAD out the door so fast in such a ramsackle establishment, I wouldn't even ask for a reference, I'd just kindly ask that they DELETE my number
> Our corporate firewall used to block any website or payload that contained the word "hack".

How else are you going to stop employees from downloading and playing NetHack at work?