▲ | hnlmorg a day ago | |||||||||||||
I’m going through exactly this joy with a client right now. “We need SQL injection rules in the WAF” “But we don’t have an SQL database” “But we need to protect against the possibility of partnering with another company that needs to use the same datasets and wants to import them into a SQL database” In fairness, these people are just trying to do their job too. They get told by NIST (et al) and Cloud service providers that WAF is best practice. So it’s no wonder they’d trust these snake oil salesman over the developers who asking not to do something “security” related. | ||||||||||||||
▲ | zelphirkalt 16 hours ago | parent [-] | |||||||||||||
If they want to do their job well, how about adding some thinking into the mix, for good measure? Good would also be,if they actually knew what they are talking about, before trying to tell the engineers what to do. | ||||||||||||||
|