←back to thread

698 points jgrahamc | 1 comments | | HN request time: 0.201s | source
Show context
foota ◴[] No.20425631[source]
What about: WAF cpu usage wasn't isolated from the ability to serve requests? This would allow requests that don't go throwugh WAF to be able to proceed as usual.
replies(1): >>20425692 #
clinta ◴[] No.20425692[source]
A firewall that fails open sounds like a terrible plan.

As far as problems go, an outage is preferable to a breach.

replies(1): >>20426714 #
1. Thorrez ◴[] No.20426714[source]
I believe WAF is a feature customers enable, not all customers have it enabled. So some customers are already open, and in theory wouldn't need to be affected by a WAF outage.