ddactic.bsky.social
ddactic.bsky.social
@ddactic.bsky.social
Every major application-layer attack class has an HTTP version equivalent. Most defenses are written for HTTP/1.1. The gap is not theoretical.

ddactic.net?ref=bsky
August 21, 2026 at 4:19 AM
במשך כמה שנים ניהלתי בדיקות DDoS. בדקנו סביבות שונות של יצרני הגנות, ועזרתי לחברות להקשיח את תצורת ההגנה והארכיטקטורה שלהן.

ddactic.net?ref=bsky
August 21, 2026 at 4:04 AM
Showing the work of why we ship eight vendor templates instead of one universal one.

ddactic.net?ref=bsky
August 21, 2026 at 3:56 AM
A pipeline detail that explains why our hardening recommendations are never stale.

ddactic.net?ref=bsky
August 21, 2026 at 3:48 AM
A small operational detail we obsess over because it changes whether teams actually apply our recommendations.

ddactic.net?ref=bsky
August 21, 2026 at 3:40 AM
Anonymized but real. An IL insurance company with five enterprise WAF licenses and a multi-million-dollar protection budget.

ddactic.net?ref=bsky
August 21, 2026 at 3:32 AM
A doctrine I want to put on record because we get asked about it almost weekly.

ddactic.net?ref=bsky
August 21, 2026 at 3:24 AM
The taxonomy under our new hardening engine, which I want to share because it doubles as a self-audit checklist.

ddactic.net?ref=bsky
August 21, 2026 at 3:16 AM
Something I keep thinking about from the rate-limit counting post.

ddactic.net?ref=bsky
August 21, 2026 at 3:08 AM
Look at the rate limits on your production WAF right now.

ddactic.net?ref=bsky
August 21, 2026 at 3:00 AM
Your employees' stolen passwords reveal more than compromised accounts.

ddactic.net?ref=bsky
August 21, 2026 at 2:52 AM
Security teams assume TLS fingerprinting blocks bots.

ddactic.net?ref=bsky
August 21, 2026 at 2:44 AM
We reverse-engineered 20 bot detection vendors.

ddactic.net?ref=bsky
August 21, 2026 at 2:36 AM
Every vendor has a different way to tell you you're "protected." None of them give you a number you can compare across vendors, track over time, or use to justify budget.

ddactic.net?ref=bsky
August 21, 2026 at 2:28 AM
You configured a rate limit: 100 requests per 10 seconds. You tested it from your office. It works. An attacker sends 90 requests per 10 seconds from each of 10 different countries. Your CDN sees 900 requests per 10 seconds total but triggers nothing.

ddactic.net?ref=bsky
August 21, 2026 at 2:20 AM
DDoS vendors detect and block attacker IPs within minutes. Static IPs become useless fast.

ddactic.net?ref=bsky
August 21, 2026 at 2:12 AM
Every instance in our fleet runs up to 7 testing tools simultaneously. Each one can crash.

ddactic.net?ref=bsky
August 21, 2026 at 2:04 AM
Our full distributed load generation fleet costs $23.50 per hour.

ddactic.net?ref=bsky
August 21, 2026 at 1:56 AM
We added breach database lookups to our recon pipeline.

ddactic.net?ref=bsky
August 21, 2026 at 1:48 AM
We use Claude Haiku at four specific points across our six-stage recon pipeline. Not for marketing. For accuracy.

ddactic.net?ref=bsky
August 21, 2026 at 1:40 AM
We don't rely on a single source for asset discovery.

ddactic.net?ref=bsky
August 21, 2026 at 1:32 AM
Hot take: "I built this with AI" is usually the wrong message.

ddactic.net?ref=bsky
August 21, 2026 at 1:24 AM
A scrubbing center is not a guarantee. It's a routing decision, and most CISOs blur three different things into one.

ddactic.net?ref=bsky
August 21, 2026 at 1:16 AM
Every TLS certificate you've ever issued is public.

ddactic.net?ref=bsky
August 21, 2026 at 1:08 AM
We scan companies and almost always find the same thing in the subdomain list:

ddactic.net?ref=bsky
August 21, 2026 at 1:00 AM