{"id":3139,"date":"2016-12-05T11:29:05","date_gmt":"2016-12-05T18:29:05","guid":{"rendered":"https:\/\/www.whitefirdesign.com\/blog\/?p=3139"},"modified":"2016-12-05T11:29:05","modified_gmt":"2016-12-05T18:29:05","slug":"godaddy-doesnt-disclose-the-true-source-of-sitelocks-cdn-and-waf-services","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2016\/12\/05\/godaddy-doesnt-disclose-the-true-source-of-sitelocks-cdn-and-waf-services\/","title":{"rendered":"GoDaddy Doesn&#8217;t Disclose The True Source of SiteLock&#8217;s CDN and WAF Services"},"content":{"rendered":"<p>The last time we discussed GoDaddy&#8217;s partnership with SiteLock back in September it involved a situation where <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2016\/09\/14\/godaddy-and-sitelock-make-a-mess-of-a-hack-cleanup-and-drop-the-ball-on-security-as-well\/\">SiteLock managed to break a website they were supposed to be cleaning, GoDaddy was partly responsible for the website being hacked, and SiteLock failed to detect that GoDaddy issue due to their failure to do a basic part of a hack cleanup<\/a>.\u00a0Based on that an expansion of their partnership doesn&#8217;t seem like a good thing, but it is happening.<\/p>\n<p>Today GoDaddy <a href=\"https:\/\/aboutus.godaddy.net\/newsroom\/news-releases\/news-releases-details\/2016\/GoDaddy-Expands-Security-Product-Lineup-With-SiteLock-TrueShield--TrueSpeed\/default.aspx\">announced<\/a> that they would now be offering SiteLock&#8217;s content data network (CDN) and web application firewall services (WAF) services. What they neglected to mention is that these services are not actually provided by SiteLock, but as we <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2016\/11\/02\/is-sitelock-lying-about-patent-pending-technology-and-the-true-source-of-some-of-their-services\/\">recently<\/a>\u00a0<a href=\"https:\/\/www.whitefirdesign.com\/blog\/2016\/11\/08\/more-evidence-that-sitelocks-trueshield-web-application-firewall-is-really-incapsulas-waf\/\">discovered<\/a>,\u00a0by another company, Incapsula. That is a rather important item to disclose since both of those services involve sending your website&#8217;s traffic through someone else&#8217;s systems. Having a company you have no involvement with having access to all of your website&#8217;s traffic obviously raises some serious issues. Even if you are not concerned\u00a0with Incapsula having access to your traffic, it looks like SiteLock could switch to another provider at any time without you being aware of it.<\/p>\n<p>Also missing from the press release is any evidence that SiteLock&#8217;s WAF actually provides any protection (which we haven&#8217;t seen provide elsewhere either). Instead you get unsupported claims as to the protection it supposedly provides. One claim included has actually been indirectly disputed by SiteLock. That claim being that it prevents backdoor access:<\/p>\n<blockquote><p>Trust that website content will be protected from potentially harmful spam comments, and backdoor access to website files will be blocked.<\/p><\/blockquote>\n<p>In previous post we looked at situation where a <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2016\/11\/07\/looking-at-how-sitelock-sells-their-services-versus-the-reality-behind-them\/\">SiteLock customer using their firewall got hacked again<\/a>\u00a0and said that\u00a0&#8220;SiteLock assures me that everything is set up correctly, and that the hacker must have a back door access point.\u00a0 They don\u2019t cover that.&#8221;.<\/p>\n<p>If you are actually looking to keep your website\u00a0then <a href=\"http:\/\/www.whitefirdesign.com\/resources\/secure-your-website-from-hackers.html\">these are things you should focus on<\/a>, which are\u00a0not things that any SiteLock services provides. You also would probably be best off <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2016\/11\/21\/here-are-sitelocks-web-hosting-partners-you-probably-should-avoid-them\/\">not using a web host, like GoDaddy, that partners with SiteLock<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The last time we discussed GoDaddy&#8217;s partnership with SiteLock back in September it involved a situation where SiteLock managed to break a website they were supposed to be cleaning, GoDaddy was partly responsible for the website being hacked, and SiteLock failed to detect that GoDaddy issue due to their failure to do a basic part &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2016\/12\/05\/godaddy-doesnt-disclose-the-true-source-of-sitelocks-cdn-and-waf-services\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;GoDaddy Doesn&#8217;t Disclose The True Source of SiteLock&#8217;s CDN and WAF Services&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25],"tags":[63,39,99],"class_list":["post-3139","post","type-post","status-publish","format-standard","hentry","category-bad-security","tag-godaddy","tag-sitelock","tag-trueshield-web-application-firewall"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3139","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=3139"}],"version-history":[{"count":2,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3139\/revisions"}],"predecessor-version":[{"id":3141,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3139\/revisions\/3141"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=3139"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=3139"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=3139"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}