List: websecurity@lists.webappsec.org
From: Arian J. Evans
Re: [WEB SECURITY] NetSec Breaking Apps Better Than AppSec
Fri, Jul 8, 2011 11:20 PM
(insert early WAF shelfware stories here)
#5) If you have legitimate, non-confidential cookie usage (like most
web apps) and you have legitimate, non-transport encrypted traffic
(like many if not most web apps) then you will break things
arbitrarily slapping =secure on them, as I have seen both recommended
and done.