<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: What web application security really is</title>
	<atom:link href="http://www.mikeandrews.com/2008/06/17/what-web-application-security-really-is/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mikeandrews.com/2008/06/17/what-web-application-security-really-is/</link>
	<description></description>
	<lastBuildDate>Fri, 09 Apr 2010 12:01:55 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: VA+WAF: that&#8217;s hot! &#124; Mike Andrews</title>
		<link>http://www.mikeandrews.com/2008/06/17/what-web-application-security-really-is/comment-page-1/#comment-195</link>
		<dc:creator>VA+WAF: that&#8217;s hot! &#124; Mike Andrews</dc:creator>
		<pubDate>Fri, 20 Jun 2008 05:47:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.mikeandrews.com/2008/06/17/what-web-application-security-really-is/#comment-195</guid>
		<description>[...] the &#8220;hot&#8221; topic in webappsec this week.&#160; First up we have the ts/sci post that I linked to earlier, Andre responded, and we also have a post from the guys at [...]</description>
		<content:encoded><![CDATA[<p>[...] the &#8220;hot&#8221; topic in webappsec this week.&nbsp; First up we have the ts/sci post that I linked to earlier, Andre responded, and we also have a post from the guys at [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andre Gironda</title>
		<link>http://www.mikeandrews.com/2008/06/17/what-web-application-security-really-is/comment-page-1/#comment-193</link>
		<dc:creator>Andre Gironda</dc:creator>
		<pubDate>Wed, 18 Jun 2008 12:11:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.mikeandrews.com/2008/06/17/what-web-application-security-really-is/#comment-193</guid>
		<description>If developers are so hard to work with, so miserably stupid, and so unwilling to develop with security in mind -- then how can a WAF vendor write secure software for their own products?  This is the classic example of where a security vendor assumes that their own products are secure just because they are a security company.

If a WAF is insecure -- then it adds to the insecurity of the network more than it subtracts from it.  This hurts the &quot;defense in depth&quot; architecture and it weakens the system/infrastructure as a whole.  Thus, it is bad.

If there are &lt;i&gt;some&lt;/i&gt; benefits to WAF&#039;s &lt;i&gt;some&lt;/i&gt; of the time, then we should be specific about when those events are.  Let&#039;s identify them.  I can&#039;t think of any situations where this universally applies.  However, the rest of the industry analysts and popular theory is that WAF&#039;s (or VA+WAF) are magical beans.  I am simply trying to dispel that theory, based on my own experiences and observations.

If you have a story where you know WAF works, let&#039;s hear it.  Yet, everyday, I hear about websites in the news -- websites that utilize WAF technology -- and they are vulnerable to various SQLi and XSS attacks.  SQLi and XSS are some of the only web application vulnerabilities that WAF is supposed to protect against.  If WAF&#039;s can&#039;t even protect against these, how are they ever going to be able to protect against business logic flaws, vulnerabilities in session management, cryptographic storage, or the hundreds of other common flaws in web applications?

What is the value?  How are they showing value?  Why is it assumed that they are valuable?  My strawman presupposition is that they universally hurt more than they help.  Am I wrong?  In what way?

After this dust is settled, there is still the question of what works better: process improvements with a secure SDLC, or VA+WAF?  I&#039;ve thought very hard about this one, and I still see secure SDLC coming out very far ahead -- even in the short-term.  What would it take to prove this?</description>
		<content:encoded><![CDATA[<p>If developers are so hard to work with, so miserably stupid, and so unwilling to develop with security in mind &#8212; then how can a WAF vendor write secure software for their own products?  This is the classic example of where a security vendor assumes that their own products are secure just because they are a security company.</p>
<p>If a WAF is insecure &#8212; then it adds to the insecurity of the network more than it subtracts from it.  This hurts the &#8220;defense in depth&#8221; architecture and it weakens the system/infrastructure as a whole.  Thus, it is bad.</p>
<p>If there are <i>some</i> benefits to WAF&#8217;s <i>some</i> of the time, then we should be specific about when those events are.  Let&#8217;s identify them.  I can&#8217;t think of any situations where this universally applies.  However, the rest of the industry analysts and popular theory is that WAF&#8217;s (or VA+WAF) are magical beans.  I am simply trying to dispel that theory, based on my own experiences and observations.</p>
<p>If you have a story where you know WAF works, let&#8217;s hear it.  Yet, everyday, I hear about websites in the news &#8212; websites that utilize WAF technology &#8212; and they are vulnerable to various SQLi and XSS attacks.  SQLi and XSS are some of the only web application vulnerabilities that WAF is supposed to protect against.  If WAF&#8217;s can&#8217;t even protect against these, how are they ever going to be able to protect against business logic flaws, vulnerabilities in session management, cryptographic storage, or the hundreds of other common flaws in web applications?</p>
<p>What is the value?  How are they showing value?  Why is it assumed that they are valuable?  My strawman presupposition is that they universally hurt more than they help.  Am I wrong?  In what way?</p>
<p>After this dust is settled, there is still the question of what works better: process improvements with a secure SDLC, or VA+WAF?  I&#8217;ve thought very hard about this one, and I still see secure SDLC coming out very far ahead &#8212; even in the short-term.  What would it take to prove this?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
