Hacker News new | ask | show | jobs
by threeseed 956 days ago
WAF don't require a team of security engineers to babysit.

Cloudflare, AWS, GCP etc offerings are basically just one click and for smaller sites will be free.

And over the years there have been many security flaws in how SQL libraries actually handle parameterisation.

1 comments

That "one click" instantly broke every single application I've seen it applied to.

Eliminating false positives is a significant effort.