<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Week of War on WAF&#8217;s: Day 1 &#8212; Top ten reasons to wait on WAF&#8217;s</title>
	<link>http://www.tssci-security.com/archives/2008/06/23/week-of-war-on-wafs-day-1-top-ten-reasons-to-wait-on-wafs/</link>
	<description>top secret/secure computing information</description>
	<pubDate>Tue, 14 Oct 2008 11:10:08 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Rafal</title>
		<link>http://www.tssci-security.com/archives/2008/06/23/week-of-war-on-wafs-day-1-top-ten-reasons-to-wait-on-wafs/#comment-8325</link>
		<dc:creator>Rafal</dc:creator>
		<pubDate>Tue, 01 Jul 2008 12:28:47 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2008/06/23/week-of-war-on-wafs-day-1-top-ten-reasons-to-wait-on-wafs/#comment-8325</guid>
		<description>OK - thoughts on your top 10:
1) Duh?  Same reason most app apps won't say what they're vulnerable to - I thought this would be common sense.
2) Agreed - a painful point
3) Agreed - interesting though...
4) No truth in advertising?  Really?  Noooo?  (I'm layering on the sarcasm to make a point, everyone hypes their product; it's the way things work)
5) There are but a few "desperate" vendors out there; and those are the ones who can't sell their product (the rest are fine)
6) This isn't shocking... programming a web app isn't the same as writing a defensive tool - I know it sounds idiotic...
7) Bold claim - I'd love to see you back this one up with an actual fact
8 &#38; 9) Same point - but worth mentioning.  These are just inherent limitations to automated technology - and will likely never be solved by a WAF or other tools - developers have to solve this problem
10) Agreed, and those are likely the more sound solutions - but alas... as I wrote yesterday in an article on this topic... this is the "throw in a box and you'll meet the requirement" solution.  What CIO wouldn't love one of these?

Good points, but you've got to back up some of your very bold claims, otherwise you'll be accused of spreading the FUD you are preaching against.  Careful, you have to be accountable as a critic lest you become as your target.</description>
		<content:encoded><![CDATA[<p>OK - thoughts on your top 10:<br />
1) Duh?  Same reason most app apps won&#8217;t say what they&#8217;re vulnerable to - I thought this would be common sense.<br />
2) Agreed - a painful point<br />
3) Agreed - interesting though&#8230;<br />
4) No truth in advertising?  Really?  Noooo?  (I&#8217;m layering on the sarcasm to make a point, everyone hypes their product; it&#8217;s the way things work)<br />
5) There are but a few &#8220;desperate&#8221; vendors out there; and those are the ones who can&#8217;t sell their product (the rest are fine)<br />
6) This isn&#8217;t shocking&#8230; programming a web app isn&#8217;t the same as writing a defensive tool - I know it sounds idiotic&#8230;<br />
7) Bold claim - I&#8217;d love to see you back this one up with an actual fact<br />
8 &amp; 9) Same point - but worth mentioning.  These are just inherent limitations to automated technology - and will likely never be solved by a WAF or other tools - developers have to solve this problem<br />
10) Agreed, and those are likely the more sound solutions - but alas&#8230; as I wrote yesterday in an article on this topic&#8230; this is the &#8220;throw in a box and you&#8217;ll meet the requirement&#8221; solution.  What CIO wouldn&#8217;t love one of these?</p>
<p>Good points, but you&#8217;ve got to back up some of your very bold claims, otherwise you&#8217;ll be accused of spreading the FUD you are preaching against.  Careful, you have to be accountable as a critic lest you become as your target.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Cody</title>
		<link>http://www.tssci-security.com/archives/2008/06/23/week-of-war-on-wafs-day-1-top-ten-reasons-to-wait-on-wafs/#comment-8086</link>
		<dc:creator>Tom Cody</dc:creator>
		<pubDate>Wed, 25 Jun 2008 06:39:38 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2008/06/23/week-of-war-on-wafs-day-1-top-ten-reasons-to-wait-on-wafs/#comment-8086</guid>
		<description>The big problem with the new hype "WAF" is that managers of bigger companies who decide to buy and implement WAFs have not enough technical skills and background to evaluate if they are really necessary. The vendors have a lot of colorful presentation sheets to lure these guys into buying them to feel safe and sound. Even if managers ask technically skilled employees they don't care much about in their opinion especially if there's already a lobby for WAFs.

Moreover, managers have a certain budget for security and spend it on invest and not on additional staff (e.g. for improving the code quality) since invest is a one time deal (not regarding the maintenance fees now), and not running expenses.

Well, this is an oberservation of a really big company (&#62;10000 employees) and I just ewanted to share............</description>
		<content:encoded><![CDATA[<p>The big problem with the new hype &#8220;WAF&#8221; is that managers of bigger companies who decide to buy and implement WAFs have not enough technical skills and background to evaluate if they are really necessary. The vendors have a lot of colorful presentation sheets to lure these guys into buying them to feel safe and sound. Even if managers ask technically skilled employees they don&#8217;t care much about in their opinion especially if there&#8217;s already a lobby for WAFs.</p>
<p>Moreover, managers have a certain budget for security and spend it on invest and not on additional staff (e.g. for improving the code quality) since invest is a one time deal (not regarding the maintenance fees now), and not running expenses.</p>
<p>Well, this is an oberservation of a really big company (&gt;10000 employees) and I just ewanted to share&#8230;&#8230;&#8230;&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Armando Romeo</title>
		<link>http://www.tssci-security.com/archives/2008/06/23/week-of-war-on-wafs-day-1-top-ten-reasons-to-wait-on-wafs/#comment-8062</link>
		<dc:creator>Armando Romeo</dc:creator>
		<pubDate>Tue, 24 Jun 2008 16:13:01 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2008/06/23/week-of-war-on-wafs-day-1-top-ten-reasons-to-wait-on-wafs/#comment-8062</guid>
		<description>dre, I was agreeing with you and criticising with the false sense of security they sell. 
Indeed, I agree with everything you said in my response. I realize I wasn't clear in my first comment. 
First of all, I don't hate WAF, when they are used as a further layer of security (after a real assessment/pen testing or better source code analysis). Having that said let's go on.

Compliances for some clients are just a way to show they care about customers data, and that if anything wrong (read disaster or read TJX) happens at least they can show good intentions against the court. And a WAF is considered "good intention" as of now.  As good as a source code analysis. It's sad but it's what we have now.

The false sense of security is to blame to WAF vendors. While the increasing number of WAF sales is due to those (compliance) papers that makes them comparable to real security.
I would call it irresponsible. Yes.
WAF vendors sell more. 
Companies can show they care and that they are compliant, that now means secure, saving on money.
The only party losing from all of this is the final customer.</description>
		<content:encoded><![CDATA[<p>dre, I was agreeing with you and criticising with the false sense of security they sell.<br />
Indeed, I agree with everything you said in my response. I realize I wasn&#8217;t clear in my first comment.<br />
First of all, I don&#8217;t hate WAF, when they are used as a further layer of security (after a real assessment/pen testing or better source code analysis). Having that said let&#8217;s go on.</p>
<p>Compliances for some clients are just a way to show they care about customers data, and that if anything wrong (read disaster or read TJX) happens at least they can show good intentions against the court. And a WAF is considered &#8220;good intention&#8221; as of now.  As good as a source code analysis. It&#8217;s sad but it&#8217;s what we have now.</p>
<p>The false sense of security is to blame to WAF vendors. While the increasing number of WAF sales is due to those (compliance) papers that makes them comparable to real security.<br />
I would call it irresponsible. Yes.<br />
WAF vendors sell more.<br />
Companies can show they care and that they are compliant, that now means secure, saving on money.<br />
The only party losing from all of this is the final customer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dre</title>
		<link>http://www.tssci-security.com/archives/2008/06/23/week-of-war-on-wafs-day-1-top-ten-reasons-to-wait-on-wafs/#comment-8060</link>
		<dc:creator>dre</dc:creator>
		<pubDate>Tue, 24 Jun 2008 15:43:45 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2008/06/23/week-of-war-on-wafs-day-1-top-ten-reasons-to-wait-on-wafs/#comment-8060</guid>
		<description>@ Armando Romeo:

Yes, we can't blame the vendors for the PCI-DSS standard.  However, with the dollars they are spending on advertising, combined with the pull they have in other areas of marketing -- I think we should hold them accountable for building this false sense of security.  It's just like they used to say about amateur/home-grown cryptography that was sold as commercial-quality/safe -- something we used to call "silicon snake-oil".

Also -- I don't really understand your argument.  You think that customers that only want compliance should be allowed to do what they want.  I agree -- but they should be able to make educated decisions using fair and balanced information.  While compliance may be misguided; WAF vendors' marketing towards potential customers by using WAF as the primary control to meet a compliance standard for security purposes is misleading.  Wouldn't you call that (at the very least) irresponsible?</description>
		<content:encoded><![CDATA[<p>@ Armando Romeo:</p>
<p>Yes, we can&#8217;t blame the vendors for the PCI-DSS standard.  However, with the dollars they are spending on advertising, combined with the pull they have in other areas of marketing &#8212; I think we should hold them accountable for building this false sense of security.  It&#8217;s just like they used to say about amateur/home-grown cryptography that was sold as commercial-quality/safe &#8212; something we used to call &#8220;silicon snake-oil&#8221;.</p>
<p>Also &#8212; I don&#8217;t really understand your argument.  You think that customers that only want compliance should be allowed to do what they want.  I agree &#8212; but they should be able to make educated decisions using fair and balanced information.  While compliance may be misguided; WAF vendors&#8217; marketing towards potential customers by using WAF as the primary control to meet a compliance standard for security purposes is misleading.  Wouldn&#8217;t you call that (at the very least) irresponsible?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Armando Romeo</title>
		<link>http://www.tssci-security.com/archives/2008/06/23/week-of-war-on-wafs-day-1-top-ten-reasons-to-wait-on-wafs/#comment-8059</link>
		<dc:creator>Armando Romeo</dc:creator>
		<pubDate>Tue, 24 Jun 2008 15:27:05 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2008/06/23/week-of-war-on-wafs-day-1-top-ten-reasons-to-wait-on-wafs/#comment-8059</guid>
		<description>I never believed into WAF's as a solution. 
But as long as compliances like PCI makes it a valid alternative to a *real* source code auditing or penetration testing job then we can't blame WAF vendors. They are just selling what clients want. And clients do not always want security, sometimes they only want compliance.</description>
		<content:encoded><![CDATA[<p>I never believed into WAF&#8217;s as a solution.<br />
But as long as compliances like PCI makes it a valid alternative to a *real* source code auditing or penetration testing job then we can&#8217;t blame WAF vendors. They are just selling what clients want. And clients do not always want security, sometimes they only want compliance.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: romain</title>
		<link>http://www.tssci-security.com/archives/2008/06/23/week-of-war-on-wafs-day-1-top-ten-reasons-to-wait-on-wafs/#comment-8054</link>
		<dc:creator>romain</dc:creator>
		<pubDate>Tue, 24 Jun 2008 13:20:36 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2008/06/23/week-of-war-on-wafs-day-1-top-ten-reasons-to-wait-on-wafs/#comment-8054</guid>
		<description>It's interesting how people think that a WAF can do a great job. This is just a tool to prevent script kiddies to attack using some variation of the [Enter Whatever Letter You Want]Snake Cheat Sheet!

A WAF (in production) cannot be an intelligent tool, cause I believe this is too risky for many companies; they want to know why a possible customer has been drop off their site like that, therefore, it's only rules based. Big limitation, it's only made of what we actually know...</description>
		<content:encoded><![CDATA[<p>It&#8217;s interesting how people think that a WAF can do a great job. This is just a tool to prevent script kiddies to attack using some variation of the [Enter Whatever Letter You Want]Snake Cheat Sheet!</p>
<p>A WAF (in production) cannot be an intelligent tool, cause I believe this is too risky for many companies; they want to know why a possible customer has been drop off their site like that, therefore, it&#8217;s only rules based. Big limitation, it&#8217;s only made of what we actually know&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.423 seconds -->
