Reasons Not To Use A WAF
A WAF, or a Web Application Firewall, sounds like a good way to protect your services.
Most companies use WAFs because it’s an easy way to check off an item for certain compliance frameworks.
Here are some reasons why you might want to reconsider using a WAF:
- False Positives and Negatives: You can block legitimate traffic or fail to detect legitimate threats.
- Zero-Days: WAFs can’t detect Zero-Day vulnerabilities.
- Performance Impact: A WAF is like a main in the middle for your traffic that scans its contents. The scanning will increase the latency of your services.
- Microservices Architecture: WAFs are less effective with a microservices architecture due to an increased surface area and the number of custom rules that need to be created and maintained.
If you’re still curious and want to learn more, here’s some additional reading:
- https://www.macchaffee.com/blog/2023/wafs/
- https://security.stackexchange.com/questions/273357/whats-wrong-with-the-use-of-a-waf-web-application-firewall
Master GitHub Actions with a Senior Infrastructure Engineer
As a senior staff infrastructure engineer, I share exclusive, behind-the-scenes insights that you won't find anywhere else. Get the strategies and techniques I've used to save companies $500k in CI costs and transform teams with GitOps best practices—delivered straight to your inbox.
Not sure yet? Check out the archive.
Unsubscribe at any time.