Home/Security
Topic

Security

1,018 articles on Security.

11,834 articles
Security — DDoS threat report for 2024 Q3

DDoS threat report for 2024 Q3

Welcome to the 19th edition of the Cloudflare DDoS Threat Report. Released quarterly, these reports provide an in-depth analysis of the DDoS threat landscape as observed across the Cloudflare network. This edition focuses on the third quarter of 2024.

OJOmer, JorgeOmer, Jorge·October 23, 2024Security
Security — IPLS: Privacy-preserving storage for your WhatsApp contacts

IPLS: Privacy-preserving storage for your WhatsApp contacts

Your contact list is fundamental to the experiences you love and enjoy on WhatsApp. With contacts, you know which of your friends and family are on WhatsApp, you can easily message or call them, and it helps give you context on who is in your groups. But losing your phone could mean losing your contact […]

CWChris Wiltz·October 22, 2024Security
Security — ktls now under the rustls org

ktls now under the rustls org

What’s a ktls I started work on ktls and ktls-sys , a pair of crates exposing Kernel TLS offload to Rust, about two years ago . kTLS lets the kernel (and, in turn, any network interface that supports it) take care of encryption, framing, etc., for the entire duration of a TLS connection… as soon as you have a TLS connection. For the handshake itself (hellos, change cipher, encrypted extensions, ce

AWAmos WengerAmos Wenger·September 26, 2024Security
Security — Cloudflare helps verify the security of end-to-end encrypted messages by auditing key transparency for WhatsApp

Cloudflare helps verify the security of end-to-end encrypted messages by auditing key transparency for WhatsApp

Cloudflare is now verifying WhatsApp’s Key Transparency audit proofs to ensure the security of end-to-end encrypted messaging conversations without having to manually check QR codes. We are publishing the results of the proof verification to https://dash.key-transparency.cloudflare.com for independent researchers and security experts to compare against WhatsApp’s. Cloudflare does not have access t

TMThibault, MariThibault, Mari·September 24, 2024Security
Security — How Cloudflare is helping domain owners with the upcoming Entrust CA distrust by Chrome and Mozilla

How Cloudflare is helping domain owners with the upcoming Entrust CA distrust by Chrome and Mozilla

Chrome and Mozilla will stop trusting Entrust’s public TLS certificates issued after November 2024 due to concerns about Entrust’s compliance with security standards. In response, Entrust is partnering with SSL.com to continue providing trusted certificates. Cloudflare will support SSL.com as a CA, simplifying certificate management for customers using Entrust by automating issuance and renewals.

DDinaDina·September 19, 2024Security
Security — Protecting APIs from abuse using sequence learning and variable order Markov chains

Protecting APIs from abuse using sequence learning and variable order Markov chains

At Cloudflare, we protect customer APIs from abuse. This is no easy task, as abusive traffic can take different forms, from giant DDoS attacks to low-and-slow credential stuffing campaigns. We now address this challenge in a new way: by looking outside typical volumetric measures and using statistical machine learning to find important API client request sequences.

PFPeter FosterPeter Foster·September 12, 2024Security
Security — How Meta enforces purpose limitation via Privacy Aware Infrastructure at scale

How Meta enforces purpose limitation via Privacy Aware Infrastructure at scale

At Meta, we’ve been diligently working to incorporate privacy into different systems of our software stack over the past few years. Today, we’re excited to share some cutting-edge technologies that are part of our Privacy Aware Infrastructure (PAI) initiative. These innovations mark a major milestone in our ongoing commitment to honoring user privacy. PAI offers […]

CWChris Wiltz·August 27, 2024Security
Security — A wild week in phishing, and what it means for you

A wild week in phishing, and what it means for you

From the U.S. elections and geopolitical conflict to tens of millions in corporate dollars lost, phishing remains the root cause of cyber damages. Learn why a comprehensive solution is the best way to stay protected.

PPPete PangPete Pang·August 16, 2024Security
Security — Application Security report: 2024 update

Application Security report: 2024 update

Cloudflare’s updated 2024 view on Internet cyber security trends spanning global traffic insights, bot traffic insights, API traffic insights, and client-side risks

MTMichael Tremante, SabinaMichael Tremante, Sabina·July 11, 2024Security
Security — DDoS threat report for 2024 Q2

DDoS threat report for 2024 Q2

Welcome to the 18th edition of the Cloudflare DDoS Threat Report. Released quarterly, these reports provide an in-depth analysis of the DDoS threat landscape as observed across the Cloudflare network. This edition focuses on the second quarter of 2024

OJOmer, JorgeOmer, Jorge·July 9, 2024Security
Security — RADIUS/UDP vulnerable to improved MD5 collision attack

RADIUS/UDP vulnerable to improved MD5 collision attack

The RADIUS protocol is commonly used to control administrative access to networking gear. Despite its importance, RADIUS hasn’t changed much in decades. We discuss an attack on RADIUS as a case study for why it’s important for legacy protocols to keep up with advancements in cryptography

GMGoldbe, Miro HallerGoldbe, Miro Haller·July 9, 2024Security
Security — Proactive Measures Against Password Breaches and Cookie Hijacking

Proactive Measures Against Password Breaches and Cookie Hijacking

At Slack, we’re committed to security that goes beyond the ordinary. We continuously strive to earn and maintain user trust by safeguarding critical components integral to every user’s experience. From passwords to session cookies, and tokens to webhooks, we prioritize protecting everything essential to how users log into the platform and remain authenticated. Through proactive…

NLNathan Lehotsky·June 28, 2024Security
Security — Cloudflare incident on June 20, 2024

Cloudflare incident on June 20, 2024

A new DDoS rule resulted in an increase in error responses and latency for Cloudflare customers. Here’s how it went wrong, and what we’ve learned

LJLloyd, Julien DesgatsLloyd, Julien Desgats·June 26, 2024Security
Security — Celebrating 10 years of Project Galileo

Celebrating 10 years of Project Galileo

On its 10th anniversary, Cloudflare's Project Galileo continues to offer free security services to over 2,600 journalists and nonprofits globally, supporting human rights and democracy.

MPMatthew Prince, Alissa StarzakMatthew Prince, Alissa Starzak·June 12, 2024Security
Security — Post-quantum readiness for TLS at Meta

Post-quantum readiness for TLS at Meta

Today, the internet (like most digital infrastructure in general) relies heavily on the security offered by public-key cryptosystems such as RSA, Diffie-Hellman (DH), and elliptic curve cryptography (ECC). But the advent of quantum computers has raised real questions about the long-term privacy of data exchanged over the internet. In the future, significant advances in quantum […]

CWChris Wiltz·May 22, 2024Security
Security — Securing millions of developers through 2FA

Securing millions of developers through 2FA

We’ve dramatically increased 2FA adoption on GitHub as part of our responsibility to make the software ecosystem more secure. Read on to learn how we secured millions of developers and why we’re urging more organizations to join us in these efforts.

MHMike HanleyMike Hanley·April 24, 2024Security