I'm setting up a new VPS, and I'm strongly considering turning off mod_security2 and mod_unique_id. I understand that there's a significant performance hit from them, and I don't use mod_unique_id in any of my written applications. When I turned it off, though, it took mod_security2 with it.
Since I'm using CSF, do I really need mod_security2?
Then today I see that WHM recommends setting up modsec2-rules-owasp-crs... which, of course, requires mod_security2 and mod_unique_id.
So now I'm back to same question... since I'm using CSF, do I even need this? Is it worth the performance hit?
For me, my main sites make money through Adsense and I've found that the faster the site runs, the more pages per session I get. So if each page load speeds up by 500ms, that could result in a significant bump in revenue for me... but it's not worth it if I'm going to get hit by a ton of scams or viruses.
Since I'm using CSF, do I really need mod_security2?
Then today I see that WHM recommends setting up modsec2-rules-owasp-crs... which, of course, requires mod_security2 and mod_unique_id.
So now I'm back to same question... since I'm using CSF, do I even need this? Is it worth the performance hit?
For me, my main sites make money through Adsense and I've found that the faster the site runs, the more pages per session I get. So if each page load speeds up by 500ms, that could result in a significant bump in revenue for me... but it's not worth it if I'm going to get hit by a ton of scams or viruses.