Home/Security
Topic

Security

1,018 articles on Security.

11,834 articles
Security — The little bug that couldn’t: Securing OpenSSL

The little bug that couldn’t: Securing OpenSSL

Software security doesn’t end at the boundaries of your own code. The moment a library dependency is introduced, you’re adopting other people’s code and any bugs that come with it.…

AGAgustin GianniAgustin Gianni·February 25, 2021Security
Security — Avoiding npm substitution attacks

Avoiding npm substitution attacks

Supply chain attacks are a reality in modern software development. Thankfully, you can reduce the attack surface by taking precautions and being thoughtful about how you manage your dependencies. We…

IZIsaac Z. SchlueterIsaac Z. Schlueter·February 12, 2021Security
Security — WordPress 5.7: Big ol' jQuery Update

WordPress 5.7: Big ol' jQuery Update

WordPress core is making the jump from jQuery 1.12.4 to jQuery 3.5.1! This is a big deal for lots of reasons — like modern features, better DX, and security

GGGeoff GrahamGeoff Graham·February 11, 2021Security
Security — 2020 U.S. Election: Cybersecurity Analysis

2020 U.S. Election: Cybersecurity Analysis

As we protect many entities in the election space, we have the ability to identify, learn and analyze attack trends targeted at these sites that provide authoritative election information.

JJocelynJocelyn·February 9, 2021Security
Security — Network-layer DDoS attack trends for Q4 2020

Network-layer DDoS attack trends for Q4 2020

DDoS attack trends in the final quarter of 2020 defied norms in many ways. For the first time in 2020, Cloudflare observed an increase in the number of large DDoS attacks. Specifically, the number of attacks over 500Mbps and 50K pps saw a massive uptick.

VOVivek, OmerVivek, Omer·January 22, 2021Security
Security — Women in Security at Slack

Women in Security at Slack

Since its inception, Slack has fostered a culture of inclusion and diversity. The Security organization at Slack is a prime example of how women can thrive in the security space, transitioning to security from different backgrounds and expertises. With Slack’s strong commitment to diversity, it should not be a surprise that nearly a third of…

SKSuzanna Khatchatrian·January 20, 2021Security
Security — KEMTLS: Post-quantum TLS without signatures

KEMTLS: Post-quantum TLS without signatures

The TLS 1.3 protocol has been around for quite some time, but it will be broken once quantum computers arrive. What can we do? In this blog post, we will examine a technique for achieving full post-quantum security for TLS 1.3 in the face of quantum computers: KEMTLS.

STSofia, ThomSofia, Thom·January 15, 2021Security
Security — Untangling Compliance: Working Toward a Global Framework

Untangling Compliance: Working Toward a Global Framework

As part of Cloudflare’s recent Privacy Week we hosted a series of fireside chats on security, privacy, and compliance. Many of these conversations touched on the intricate legal debate being held in Europe around data sovereignty. Here are some of the highlights.

JKJason KincaidJason Kincaid·January 11, 2021Security
Security — Ransom DDoS attacks target a Fortune Global 500 company

Ransom DDoS attacks target a Fortune Global 500 company

In late 2020, a major Fortune Global 500 company was targeted by a Ransom DDoS (RDDoS) attack by a group claiming to be the Lazarus Group. Cloudflare quickly onboarded them to the Magic Transit service and protected them against the lingering threat.

OOmerOmer·January 7, 2021Security
Security — Holiday Season Update from Lisbon

Holiday Season Update from Lisbon

Cloudflare Lisbon has come a long way. We now have 74 incredibly talented people working or joining in areas such as Engineering, Security, Infrastructure, Customer Support, People, Places, Product Management, Emerging Technologies or Accounting, and growing fast.

CCelsoCelso·December 24, 2020Security
Security — Happy anniversary GitHub Security Lab!

Happy anniversary GitHub Security Lab!

Last year at GitHub Universe, we introduced the GitHub Security Lab, which is committed to contributing resources, tooling, bounties, and security research to secure the open source ecosystem. We know…

JCJamie CoolJamie Cool·December 18, 2020Security
Security — Shifting supply chain security left with dependency review

Shifting supply chain security left with dependency review

Dependency review allows you to easily understand your dependencies before you introduce them to your environment. As part of a pull request, you can see what dependencies you’re introducing, changing, or removing, and information about their vulnerabilities, age, usage, and license.

WBWilliam BartholomewWilliam Bartholomew·December 17, 2020Security
Security — Cloudflare Certifications

Cloudflare Certifications

We think trust is fundamental to building a better Internet. Cloudflare adheres to industry-standard security compliance certifications and regulations to help our customers earn their users’ trust.

LLingLing·December 10, 2020Security
Security — Good-bye ESNI, hello ECH!

Good-bye ESNI, hello ECH!

A deep dive into the Encrypted Client Hello, a standard that encrypts privacy-sensitive parameters sent by the client, as part of the TLS handshake.

CPChristopher PattonChristopher Patton·December 8, 2020Security
Security — OPAQUE & PAKE Protocols

OPAQUE & PAKE Protocols

OPAQUE is a PAKE protocol that allows for password authentication without revealing the actual password to a server. Learn more about the OPAQUE protocol.

TTatianaTatiana·December 8, 2020Security
Security — Introducing the Cloudflare Data Localization Suite

Introducing the Cloudflare Data Localization Suite

The Data Localization Suite helps businesses get the performance and security benefits of Cloudflare’s global network while making it easy to set rules and controls at the edge about where their data is stored and protected.

JGJohn Graham CummingJohn Graham Cumming·December 7, 2020Security
Security — Applying DevSecOps to your software supply chain

Applying DevSecOps to your software supply chain

To best apply DevSecOps principles to improve the security of your supply chain, you should ask your developers to declare your dependencies in code; and in turn provide your developers with maintained ‘golden’ artifacts and automated downstream actions so they can focus on code.

MKMaya KaczorowskiMaya Kaczorowski·December 3, 2020Security
Security — Securing the fight against COVID-19 through open source

Securing the fight against COVID-19 through open source

This blog describes a security vulnerability in the infrastructure that supports Germany’s COVID-19 contact tracing efforts. The mobile (Android/iOS) apps are not affected by the vulnerability and do not collect and/or transmit any personal data other than the device’s IP address. The infrastructure takes active measures to disassociate true positives from client IP addresses.

AMAlvaro MunozAlvaro Munoz·November 19, 2020Security
Security — Network-layer DDoS attack trends for Q3 2020

Network-layer DDoS attack trends for Q3 2020

In Q3 ‘20, Cloudflare observed a surge in DDoS attacks, with double the number of DDoS attacks and more attack vectors deployed than ever — with a notable surge in protocol-specific DDoS attacks such as mDNS, Memcached, and Jenkins amplification floods.

VOVivek, OmerVivek, Omer·November 18, 2020Security
Security — Anchoring Trust: A Hardware Secure Boot Story

Anchoring Trust: A Hardware Secure Boot Story

As a security company, we pride ourselves on finding innovative ways to protect our platform to, in turn, protect the data of our customers. Part of this approach is implementing progressive methods in protecting our hardware at scale.

DCDerek Chamorro, Ryan ChowDerek Chamorro, Ryan Chow·November 17, 2020Security
Security — When trusted relationships are formed, everyone wins!

When trusted relationships are formed, everyone wins!

Monday Mornings with Customer Success: A monthly series brought to you by our Customer Success Team. This month's post is all about how building trusted relationships resulted in an improved security posture and better solution for one of our customers.

JJJake JonesJake Jones·November 16, 2020Security
Security — SAD DNS Explained

SAD DNS Explained

Researchers from UC Riverside and Tsinghua University found a new way to revive a decade-old DNS cache poisoning attack. Read our deep dive into how the SAD DNS attack on DNS resolvers works, how we protect against this attack in 1.1.1.1, and what the future holds for DNS cache poisoning attacks.

MNMarek, Nick SullivanMarek, Nick Sullivan·November 13, 2020Security
Security — Authenticating React Apps With Auth0 — Smashing Magazine

Authenticating React Apps With Auth0 — Smashing Magazine

An important aspect of app development is ensuring that only verified users have access to our apps. This can be tedious and costly do, especially when you add alternative methods of logging in outside emails and passwords. Auth0 is a service that provides authentication functionalities to developers out of the box. In this article, we’ll learn how to authenticate our React apps using Auth0. We wi

NENefe Emadamerho AtoriNefe Emadamerho Atori·November 11, 2020Security
Security — ShiftLeft on Refactoring a Live SaaS Environment - High Scalability -

ShiftLeft on Refactoring a Live SaaS Environment - High Scalability -

This is guest a post by Preetam Jinka, Senior Infrastructure Engineer at ShiftLeft. Originally published here. ShiftLeft NextGen Static Analysis (NG SAST) is a software-as-a-service static analysis solution that allows developers to scan every pull request for security issues. Earlier this year we released Secrets, Security Insights, and a v4 API. Secrets and Security Insights are two new types of

HSHigh Scalability·November 2, 2020Security
Security — Exploiting a textbook use-after-free security vulnerability in Chrome

Exploiting a textbook use-after-free security vulnerability in Chrome

In this post I’ll give details about how to exploit CVE-2020-6449, a use-after-free (UAF) in the WebAudio module of Chrome that I discovered in March 2020. I’ll give an outline of the general strategy to exploit this type of UAF to achieve a sandboxed RCE in Chrome by a single click (and perhaps a 2 minute wait) on a malicious website.

MYMan Yue MoMan Yue Mo·October 27, 2020Security
Security — Authentication In Vue.js — Smashing Magazine

Authentication In Vue.js — Smashing Magazine

Every web application that handles user-specific data needs to implement authentication. Knowing how to do this is important for Vue developers, and that’s what this article aims to shed the spotlight on. Today, Precious Ndubueze brings you a tutorial that will prove to be useful for beginner developers who want to learn about authentication in Vue. In order to be able to follow along, you’ll need

PNPrecious NdubuezePrecious Ndubueze·October 27, 2020Security
Security — How To Overcome Data Onboarding Challenges For Software Products — Smashing Magazine

How To Overcome Data Onboarding Challenges For Software Products — Smashing Magazine

Data onboarding with a custom-built solution can be a difficult and error-prone process. Now imagine what happens when you increase the complexity, allowing for different file types, more users, varying sources and a greater need for security and compliance. It shouldn’t be up to your software end users to work out the kinks of your data onboarding, nor should your team have to do it. In this post

SSSuzanne ScaccaSuzanne Scacca·October 23, 2020Security
Security — A Virtual Product Management Internship Experience

A Virtual Product Management Internship Experience

In July 2020, I joined Cloudflare as a Product Management Intern on the DDoS (Distributed Denial of Service) team to enhance the benefits that Network Analytics brings to our customers. This is my experience.

SSelinaSelina·October 22, 2020Security
Security — Introducing Cloudflare One

Introducing Cloudflare One

Today we’re announcing Cloudflare One. It provides secure, fast, reliable, cost-effective network services, integrated with leading identity management and endpoint security providers.

MPMatthew PrinceMatthew Prince·October 12, 2020Security
Security — What is Cloudflare One?

What is Cloudflare One?

Today, we’re excited to share Cloudflare One™, our vision to tackle the intractable job of corporate security and networking. Run your network on Cloudflare and keep it secure.

RSRustam, SamRustam, Sam·October 12, 2020Security
Security — Know When You’ve Been DDoS’d

Know When You’ve Been DDoS’d

Today we’re announcing the availability of DDoS attack alerts. The alerts are available for free for all Cloudflare’s customers on paid plans. Learn how to create an alert.

CCloudflare·October 5, 2020Security
Security — NTS is now an RFC

NTS is now an RFC

After much hard work, NTS finally becomes an official RFC.This means that Network Time Security (NTS) is officially part of the collection of protocols that makes the Internet work.

WWatsonWatson·October 1, 2020Security
Security — Announcing support for gRPC

Announcing support for gRPC

Today we're excited to announce beta support for proxying gRPC, a next-generation protocol that allows you to build APIs at scale. With gRPC on Cloudflare, you get access to the security, reliability and performance features that you're used to having at your fingertips for traditional APIs.

AAchielAchiel·October 1, 2020Security