Emelia/Emi on Nostr: IMO the only "application firewalls" that should even be a thing are simple 'stupid' ...
IMO the only "application firewalls" that should even be a thing are simple 'stupid' ones: rate limiting, bot rejection via injected proof-of-work challenges, and "this client is spraying *known* exploits and so is clearly malicious" (requesting wp-admin on a non-wordpress site, verbatim exploit attempts towards unrelated applications, etc., *not* "potential" exploits)