|
|
|
|
|
by derefr
755 days ago
|
|
> But if you were blocking the data from being accepted in the first place you wouldn't have that data in your database to begin with. I mean, many of these dumb mistakes that someone would want their WAF to save them from, wouldn't be for leaks of user-provided PII, but rather for leaks of ops-provided secrets (e.g. connection credentials for upstream APIs), no? |
|