How to hide your origin IP properly (part 2)
how to hide your origin IP properly sounds like a narrow topic. It turns out to touch almost every part of how an edge network behaves under attack.Protecting the originNone of this…
how to hide your origin IP properly sounds like a narrow topic. It turns out to touch almost every part of how an edge network behaves under attack.Protecting the originNone of this…
This post is about a practical checklist for surviving Black Friday traffic. It started, as most of our posts do, with an incident that did not go the way we expected.Lessons for…
We get asked about protecting WordPress login and XML-RPC from abuse more than almost anything else, so here is the long answer.Testing in production, safelyEvery rule starts in log mode. We replay…
Here is a question we could not answer well a year ago: what really happens with keeping search engine bots happy while blocking scrapers? We can answer it now.Protecting the originNone of…
We get asked about choosing between DNS delegation and CNAME onboarding more than almost anything else, so here is the long answer.Protecting the originNone of this matters if the attacker can reach…
keeping search engine bots happy while blocking scrapers sounds like a narrow topic. It turns out to touch almost every part of how an edge network behaves under attack.Latency budgetOur budget for…
We get asked about protecting WordPress login and XML-RPC from abuse more than almost anything else, so here is the long answer.Challenges beat blocksBlocking lists go stale within minutes when attackers rotate…
Here is a question we could not answer well a year ago: what really happens with choosing between DNS delegation and CNAME onboarding? We can answer it now.What we changedWe moved the…
Over the last few months we have spent a lot of time on running a DDoS tabletop exercise with your team. This is what we learned.Latency budgetOur budget for the whole filtering…
running a DDoS tabletop exercise with your team sounds like a narrow topic. It turns out to touch almost every part of how an edge network behaves under attack.What we changedWe moved…
Here is a question we could not answer well a year ago: what really happens with load testing through Deflecto without triggering mitigation? We can answer it now.Observability firstEvery mitigation decision is…
This post is about writing your first custom WAF rule. It started, as most of our posts do, with an incident that did not go the way we expected.Compliance is a side…