I'm guessing it would be a bunch of Https or tls packets to Amazon domains and IPs
Yeh, Linux doesn't have to be scary these days.
Damn experts, what do they know?
Timpsons apparently has really interesting business models.
A friend of mine has worked on a few of their conferences, and apparently it's both fascinating and they come across as a genuinely wholesome business.
It's a franchise, but the franchisee (ie the shop) has complete control over what they sell and what services they provide (I dunno if there are any guard rails). So if they want to offer dry cleaning, they can. If they want to offer phone repairs, they can. If they want to only partially offer something, then they can rely on the Timpsons service network to provide the actual service (so dry cleaning without owning dry cleaning equipment).
https://www.timpson.co.uk/about-timpson
The management teams delegate authority but retain responsibility and we have only 2 rules:
- Look the part
- Put the money in the till
And apparently they look after their staff really well. Actually good/useful perks & benefits. In addition to the compassionate leave you've mentioned, I'm sure my friend said something about timpsons owning some property that they allow their staff to book for free (like free accomodation for holidays). Or maybe they do block bookings of stuff, or something. I wasn't hugely paying attention tbh.
Food literally grows itself in the ground. And yet we buy it from supermarkets. Absolute scam!
LE certs can always be "side loaded" by acme.sh or LEbot or whatever, and the reverse proxy restarted to use the new certs. So, the whole "pro subscription to use specific certs" shouldn't be a factor, except a little more work/config (so, money Vs time).
Now for my opinion...
For base security, all it's doing is looking at whatever you tell it to look at in an http request and forward/drop/block as such.
HAProxy is well battle-tested. Nginx is well battle-tested. Traefik and caddy are comparably newer contenders, but considering their adoption they are probably well battle-tested.
Which means, an established reverse proxy is only going to be as secure as the software it's forwarding traffic to.
If there happens to be some mental TLS handshake RCE that comes up, chances are they are all using the same underlying TLS library so all will be susceptible...
But at least an attacker only gets access to the reverse proxy server. Which is why it's worth having that in a locked down isolated VM, ideally built in a way that is extremely easy to rebuild (declarative configs like docker-compose and some scripts, or even something like nixos for an immutable OS).
As for add-ons... Most WAFs only look for things like XSS injection or SQL injection or exploitative HTTP request formats. Very very basic attack vectors that any decent HTTP stack and reasonably built software shouldn't have to even worry.
Any DDOS protection is more likely to blast your network connectivity, which (for self hosting) a WAF isn't going to be able to do anything about.
I'm not sure how good they actually are against a DOS attack that is caused by bugs/inefficiencies in the application. Maybe they monitor for long/increasing response times, and block further requests to them? Might cause a lot of false-positives for your users.
So, the only real benefit - that I see - are zero-day exploit protections.... and that only matters if they are built around near-realtime updates like crowdsec is. I don't know how it compares to cloudflares WAF, tho.
Any zero-day protection that isn't being managed and updated in near-realtime is about as effective as you monitoring news of your installed services/programmes and updating them regularly. Because you are likely to update your WAF and apps when you hear about those, or regular scheduled updates will deal with them before you even learn about them.
I guess there is security in layers, and if layers of security is more important than CPU consumption/response time/requests per second (ie have an abundance of processing, servicing few users, etc) then it might be a no-brainer.
The only other time I can see a generic WAF being useful is if you have rolled your own framework and HTTP stack, and are running your own software. Because, you won't get that right... So might as well have the extra protection of a WAF.
Or, I guess, with really old unsupported software.
But surely there is a newer take or fork of it?
There is also the "am I worth it" factor.
Like, what is your actual threat model?
Defend against the usual script-based attacks (IE low hanging fruit), only expose/forward ports that are actually required, use some sensible security that isolates more vulnerable systems (IE a proxy) from more sensitive (ie a database or storage), and update regularly on stable/lts branches.
Edit:
I just googled bunkerweb.
First we had firewalls. Then we got web application firewalls. Along came next generation firewalls. Now we have Next Generation Web Application Firewalls with paid features like "Pay per protected services" and "Best effort support included"
Maybe I'm just salty
So small imported EVs aren't actually a threat, then?
it only depicts the means to reach the Moon, more suitable for robotic missions that are not required to return,^[racist comment implying that robots have no right to be repatriated]^
Standard bottles of wine are generally 750ml tho. So a pint would be less.
The current small bottles are 187ml (personal?) and 375ml (half/demi).
So, 568ml just doesn't fit. And I have no idea who would actually produce them.
Don't you just touch SSH in the /boot dir after you flash, then you can SSH in as pi and password raspberry?
Baseball hats = cool.
Backwards baseball hats = rad.
Cowboy hats = manly.
The guy is trying to apply maths he doesn't understand to a situation he has no experience in to try and appear like he belongs.
Classic musk.
towerful
0 post score0 comment score
Or, the bill fails.
But all of its objectives get packaged attached to other bills that are actually required to be passed.
So you get some random bill about the shape of car exhausts which suddenly requires OS providers to verify users ages