Home/Security
Topic

Security

1,018 articles on Security.

11,834 articles
Security — Code scanning is now available!

Code scanning is now available!

Now available, code scanning is a developer-first, GitHub-native approach to easily find security vulnerabilities before they reach production.

JHJustin HutchingsJustin Hutchings·September 30, 2020Security
Security — Phishing Resistant SMS Autofill

Phishing Resistant SMS Autofill

We recently shipped support for the origin-bound draft standard for security codes delivered via SMS. This standard ensures security codes are entered in a phishing-resistant manner. It accomplishes this by binding an SMS with…

ZQZhongying QiaoZhongying Qiao·September 25, 2020Security
Security — A Year Later: Reflections on the ANZ Security Landscape

A Year Later: Reflections on the ANZ Security Landscape

It’s been one year since I joined Cloudflare as Head of Australia and New Zealand. Our team has been even more humbled by our mission to help build a better Internet and help organisations face the increased security threats COVID-19 has triggered.

RRaymondRaymond·September 24, 2020Security
Security — Join us for OctogatosConf

Join us for OctogatosConf

A free two-day single track conference live on September 24 – 25, 2020 in celebration of our culture and LatinX heritage month. You will join a live stream of interactive talks by industry experts in both Spanish, Portuguese and English, with live captioning and translation. Topics will include software development, security, technical project management, civic tech, open source, professional deve

AGAndrea GriffithsAndrea Griffiths·September 18, 2020Security
Security — Secondary DNS - Deep Dive

Secondary DNS - Deep Dive

The goal of Cloudflare operated Secondary DNS is to allow our customers with custom DNS solutions, be it on-premise or some other DNS provider, to be able to take advantage of Cloudflare's DNS performance and more recently, through Secondary Override, our proxying and security capabilities too.

AFAlex FattoucheAlex Fattouche·September 15, 2020Security
Security — State of Jamstack 2020: Data Deep Dive

State of Jamstack 2020: Data Deep Dive

The Jamstack, a modern approach to building websites and apps, delivers better performance, higher security, lower cost of scaling, and a better developer

GGGeoff GrahamGeoff Graham·September 3, 2020Security
Security — How we threat model

How we threat model

At GitHub, we spend a lot of time thinking about and building secure products—and one key facet of that is threat modeling. This practice involves bringing security and engineering teams…

RRRobert ReichelRobert Reichel·September 2, 2020Security
Security — How Argo Tunnel engineering uses Argo Tunnel

How Argo Tunnel engineering uses Argo Tunnel

Argo Tunnel provides remote access to development environments by creating secure outbound-only connections to Cloudflare’s edge network from a resource exposing it to the Internet. That model helps protect servers and resources from being vulnerable to attack by an exposed IP address.

CTChung TingChung Ting·August 27, 2020Security
Security — How to Have an Impactful Internship… Virtually

How to Have an Impactful Internship… Virtually

The start of any internship brings a wide range of emotions, from excitement to nervousness. After months of anticipating our first day at Slack, reality sunk in that this summer would be extremely different from any other. Due to the pandemic, our entire experience would be virtual. As the two interns for the Product Security…

RRoss·August 18, 2020Security
Security — July bonus Microsoft spear phishing

July bonus Microsoft spear phishing

The creators of two Microsoft phishing campaigns, that Area 1 has dubbed “Summer Bonus”, are attempting to lure unsuspecting employees into divulging their Microsoft credentials.

EElaineElaine·August 17, 2020Security
Security — DELF: Safeguarding deletion correctness in online social networks

DELF: Safeguarding deletion correctness in online social networks

What the research is: DELF is a new framework to help developers implement data deletion in modern applications. Traditional methods for implementing deletion require application developers to write repetitive, error-prone code. DELF’s main novelty lies in enabling developers to implement deletion in every product they build with minimal effort, which takes the form of annotations […]

MEMeta Engineering·August 12, 2020Security
Security — Network-layer DDoS attack trends for Q2 2020

Network-layer DDoS attack trends for Q2 2020

This quarter, we saw an increasing number of large scale attacks; both in terms of packet rate and bit rate. In fact, 88% of all DDoS attacks in 2020 that peaked above 100 Gbps were launched after shelter-in-place went into effect in March.

VOVivek, OmerVivek, Omer·August 5, 2020Security
Security — GitHub joins the Open Source Security Foundation

GitHub joins the Open Source Security Foundation

We are happy to announce that GitHub is joining the Open Source Security Foundation (OpenSSF) as a founding member, alongside Google, IBM, JPMorgan Chase, Microsoft, NCC Group, OWASP Foundation, Red Hat, and others.

JCJamie CoolJamie Cool·August 3, 2020Security
Security — Hardening your GitHub Enterprise Server

Hardening your GitHub Enterprise Server

GitHub stores your source code, releases, and a vast amount of invaluable information in issues and pull requests. While GitHub Enterprise Server (GHES), our self hosted solution, provides great security by default, administrators can take additional steps to further harden their appliance. This post will guide you through the most important settings.

LSLars SchneiderLars Schneider·July 20, 2020Security
Security — flowtrackd: DDoS Protection with Unidirectional TCP Flow Tracking

flowtrackd: DDoS Protection with Unidirectional TCP Flow Tracking

flowtrackd is a software-defined DDoS protection system that significantly improves our ability to automatically detect and mitigate even the most complex TCP-based DDoS attacks. If you are a Magic Transit customer, this feature will be enabled by default at no additional cost on July 29, 2020.

OOmerOmer·July 14, 2020Security
Security — Making the WAF 40% faster

Making the WAF 40% faster

As with all Cloudflare security products, the WAF is designed to not sacrifice performance for security, but there is always room for improvement. This blog post provides a brief overview of the latest performance improvements that were rolled out to our customers.

MMiguelMiguel·July 1, 2020Security
Security — The App Sandbox

The App Sandbox

Batten down the hatches! The app sandbox is now enabled for all web content. This is a fancy way of saying we’ve dialed up the security of the app. It wasn’t unsafe before, but it’s double safe now. What is the “app sandbox,” what is it protecting against, and why does it matter? This post…

RRoss·June 24, 2020Security
Security — Using data science and machine learning for improved customer support

Using data science and machine learning for improved customer support

In this blog post we’ll explore three tricks that can be used for data science that helped us solve real problems for our customer support group and our customers. Two for natural language processing in a customer support context and one for identifying attack Internet attack traffic.

JAJunade Ali, MalgorzataJunade Ali, Malgorzata·June 15, 2020Security
Security — Dropping hashes: an idiom used to demonstrate provenance of documents

Dropping hashes: an idiom used to demonstrate provenance of documents

There exists an idiom called “dropping a hash” which is widely understood in the security community and not widely understood elsewhere. Somewhat surprisingly, there does not appear to be a canonical explanation. I have dropped hashes before and wrote this up to explain the significance of it to non-specialists.

PMPatrick McKenziePatrick McKenzie·April 21, 2020Security
Security — Sawfish phishing campaign targets GitHub users

Sawfish phishing campaign targets GitHub users

A phishing campaign targeting our customers lures GitHub users into providing their credentials (including two-factor authentication codes). Learn more about the threat and what you can do to protect yourself.

GSGitHub SIRTGitHub SIRT·April 14, 2020Security