Cloudflare opens a formal channel for academic researchers
Cloudflare has hosted research-focused internships throughout the year, with interns collaborating across teams on research projects and typically shipping code, writing a blog post, and producing a peer-reviewed publication. Many interns have gone on to join Cloudflare full-time, maintaining ties with their universities and fostering ongoing exchanges with academia.
Last year, the company piloted a different kind of engagement by hosting Thomas Ristenpart, Associate Professor at Cornell Tech, for six months to work on a password breach alerting project. That experience proved successful enough that Cloudflare is now formalizing the arrangement as a Visiting Researcher Program.
What the program offers
Cloudflare Research currently concentrates on applied cryptography, privacy, network protocols and architecture, measurement and performance evaluation, and increasingly distributed systems. The Visiting Researcher Program is designed to strengthen collaboration with academia in these areas, with the goal of moving ideas from academic papers into deployable services that operate at global scale.
The program is open to both postdocs and full-time faculty who want to collaborate with Cloudflare Research for a period of three to twelve months. Eligibility requirements include:
- A PhD with a demonstrated research track record in peer-reviewed venues
- Relevant research experience in one of the program's focus areas
- The ability to design and execute a research agenda
Proposals will be evaluated on their potential for significant impact in one of the research domains and their likely value to both technical and academic communities. Selected projects are expected to aim for broad dissemination of results.
Further details are available on the Cloudflare Research website, alongside a description of Ristenpart's experience, summarized below.
A researcher's view of the visit
According to Ristenpart, a short-term industry visit can help senior researchers refresh their perspective on real-world problems and test whether ideas developed in the lab translate into products. Cloudflare's research organization, he notes, is comparatively small, connects closely with product teams, and works on a high-impact portfolio of projects.
Ristenpart joined Cloudflare in summer 2020 during an academic sabbatical. He worked three days a week—remotely during the pandemic—and devoted the rest of his time to advising graduate students at Cornell. His academic focus in recent years has included developing some of the first protocols for privacy-preserving password breach alerting, and Cloudflare's position as a security and privacy-focused service sitting in front of millions of websites made it a fitting environment to extend that work.
He worked with research engineers on a novel approach to breach alerting, called Might I Get Pwned (MIGP). The implementation surfaced several architectural challenges not encountered in prior academic work. The team also discovered that the Web Application Firewall (WAF) group had a related interest in breach alerting and could reuse the infrastructure being built. The work eventually contributed to the WAF breach alerting feature that launched in spring 2021.
The visit also generated new research questions. The CEO asked how the company could address the possibility of hoarding attacks against Privacy Pass, a deployed cryptographic protocol that helps customers defend against bots. That query led to a fundamental cryptographic question about whether partially oblivious pseudorandom functions could match the efficiency of standard ones. The question was explored in a collaboration between Ristenpart's academic group, the University of Washington, and Cloudflare; the result was a new protocol described in a preprint, which the parties expect to be deployed broadly.
Summing up, Ristenpart calls the visit a success and recommends the program to interested academics as it expands further.
How to participate
Researchers can find full information about the Visiting Researcher Program and express interest through the Cloudflare Research website, with the first batch of visitors expected in early 2022.



