blog.ratterobert.com

Conversation

Recent posts in reply to #6c4skba

prologic (twtxt.net)

One thing about my design here is that it would no longer incorporate "regex"-based rules like OWASP, mostly because my experience thus far has taught me that these rules are kind of overly sensitive, produce false positives and I'm not sure they are really very effective. For example, why is the point of performing SQL injection detection at the Edge using a WAF if you already handle SQL properly in the first place? (seriously does anyone still construct SQL queries by hand with effectively printf?!)

In reply to: #5qkg37q 1 month ago
prologic (twtxt.net)

@lyse I agree with this sentiment 🙌

In reply to: #6c4skba 1 month ago
Reply via email