Home/Cloudflare
Source

Cloudflare

2,099 articles from Cloudflare.

Security — A new WAF experience

A new WAF experience

The security landscape is moving fast. We invited users to help us shape a new WAF experience that enables us to evolve WAF to meet their demands and use cases

XMXmflsct, MruXmflsct, Mru·March 15, 2022Security
Engineering — Cloudflare Zaraz supports CSP

Cloudflare Zaraz supports CSP

If you have Cloudflare Zaraz enabled on your website, you don’t have to ask yourself twice if you should enable CSP because there’s no harmful collision between CSP & Cloudflare Zaraz

SBSimona BadoiuSimona Badoiu·March 15, 2022Engineering
Security — Investigating threats using the Cloudflare Security Center

Investigating threats using the Cloudflare Security Center

The data we glean from attacks trains our machine learning models and improves the efficacy of our network and application security products, but historically hasn’t been available to query directly. This week, we’re changing that

PJPatrick, JessePatrick, Jesse·March 14, 2022Security
Engineering — Introducing: Backup Certificates

Introducing: Backup Certificates

We are excited to introduce backup certificates to increase reliability of our service for anyone using the Cloudflare platform in the event of key compromises or related issues

DDinaDina·March 14, 2022Engineering
SRE & Ops — Get full observability into your Cloudflare logs with New Relic

Get full observability into your Cloudflare logs with New Relic

Correlating Cloudflare logs across your stack in New Relic One is powerful for monitoring and debugging in order to keep services safe and reliable. We’re excited to have partnered with New Relic to create a direct integration that provides this visibility

TMTanushree, Mike Neville O NeillTanushree, Mike Neville O Neill·March 14, 2022SRE & Ops
Security — Welcome to Security Week 2022!

Welcome to Security Week 2022!

Welcome to our first innovation week of the year: Security Week! In this post we will be going over Cloudflare’s security products’ history giving you an introduction to all the great announcements we have planned

MTMichael TremanteMichael Tremante·March 13, 2022Security
Engineering — International Women’s Day 2022

International Women’s Day 2022

Welcome to International Women’s Day 2022! Here at Cloudflare, we are happy to celebrate it with you! Our celebration is not only this blog post, but many events prepared for the month of March: our way of honoring Women’s History Month by showcasing women’s empowerment

SASofia, AngelaSofia, Angela·March 8, 2022Engineering
Networking — Announcing experimental DDR in 1.1.1.1

Announcing experimental DDR in 1.1.1.1

The majority of DNS queries on the Internet today are unencrypted. This post describes a new protocol, called Discovery of Designated Resolvers (DDR), that allows clients to upgrade from unencrypted DNS to encrypted DNS when only the IP address of a resolver is known.

CAChristopher, AnbangChristopher, Anbang·March 8, 2022Networking
Security — HPKE: Standardizing public-key encryption (finally!)

HPKE: Standardizing public-key encryption (finally!)

HPKE (RFC 9180) was made to be simple, reusable, and future-proof by building upon knowledge from prior PKE schemes and software implementations. This article provides an overview of this new standard, going back to discuss its motivation, design goals, and development process

CCloudflare·February 24, 2022Security
Engineering — Building Confidence in Cryptographic Protocols

Building Confidence in Cryptographic Protocols

This blogpost refers to the efforts to use formal/verification/implementation for post-quantum algorithms to achieve better assurance for them. It also touches on our Cloudflare efforts on this

TJThom, Jonathan HoylandThom, Jonathan Hoyland·February 24, 2022Engineering
Engineering — Making protocols post-quantum

Making protocols post-quantum

Post-quantum key exchange and signature algorithms come with different trade-offs that we’re familiar. How do we handle that when updating protocols, is this an opportunity to revisit the status quo?

CCloudflare·February 23, 2022Engineering
Security — BGP security and confirmation biases

BGP security and confirmation biases

On February 1, 2022, a configuration error on one of our routers caused a route leak of up to 2,000 Internet prefixes to one of our Internet transit providers. This leak lasted for 32 seconds and at a later time 7 seconds

CCloudflare·February 23, 2022Security
Engineering — Deep dive into a post-quantum signature scheme

Deep dive into a post-quantum signature scheme

How can one attest to an identity and prove it belongs to one self? And how can one do it in the face of quantum computers? In this blog post, we examine these questions and explain what post-quantum signatures are

GTGoutam Tamvada, SofiaGoutam Tamvada, Sofia·February 22, 2022Engineering
SRE & Ops — Internet is back in Tonga after 38 days of outage

Internet is back in Tonga after 38 days of outage

Tonga, the South Pacific archipelago nation (with 169 islands), was reconnected to the Internet this early morning (UTC) and is back online after successful repairs to the undersea cable that was damaged on Saturday, January 15, 2022, by the January 14, volcanic eruption

JTJoao TomeJoao Tome·February 22, 2022SRE & Ops
Engineering — The post-quantum state: a taxonomy of challenges

The post-quantum state: a taxonomy of challenges

At Cloudflare, we strive to help build a better Internet, which means a quantum-protected one. In this post, we look at the challenges for migrating to post-quantum cryptography and what lies ahead using a taxonomy

SSofiaSofia·February 21, 2022Engineering
Engineering — The quantum solace and spectre

The quantum solace and spectre

What is quantum computing and what advances have been made so far on this front? In this blog post, we will answer this question and see how to protect against quantum adversaries

CCloudflare·February 21, 2022Engineering
Security — Adding a CASB to Cloudflare Zero Trust

Adding a CASB to Cloudflare Zero Trust

Earlier today, Cloudflare announced that we have acquired Vectrix, a cloud-access security broker (CASB) company focused on solving the problem of control and visibility in the SaaS applications and public cloud providers that your team uses

SJSam, John Graham CummingSam, John Graham Cumming·February 10, 2022Security
Engineering — Happy Data Privacy Day!

Happy Data Privacy Day!

On this Data Privacy Day, we look back at how events in 2021 shaped the privacy world, and we look ahead to what 2022 may have in store

CCloudflare·January 28, 2022Engineering
Engineering — Migrating to Cloudflare Email Routing

Migrating to Cloudflare Email Routing

With Email Routing, you can effectively start receiving Emails in any of your domains for any number of custom addresses you want and forward the messages to any existing destination mailboxes

CCelsoCelso·January 27, 2022Engineering
Networking — Incorrect proxying of 24 hostnames on January 24, 2022

Incorrect proxying of 24 hostnames on January 24, 2022

On January 24, 2022, as a result of an internal product migration, 24 hostnames (including www.cloudflare.com) that were actively proxied through the Cloudflare global network were mistakenly redirected to the wrong origin

JHJeremy HartmanJeremy Hartman·January 26, 2022Networking
Security — Landscape of API Traffic

Landscape of API Traffic

More than 50% of all traffic processed by Cloudflare is API-based, and it’s growing twice as fast as traditional web traffic. This growth calls for the development of dedicated security solutions.

DDanieleDaniele·January 26, 2022Security
SRE & Ops — Tonga’s likely lengthy Internet outage

Tonga’s likely lengthy Internet outage

The latest Internet outage, in the South Pacific country of Tonga (with 169 islands), is still ongoing. It started with the large eruption of Hunga Tonga–Hunga Haʻapai, an uninhabited volcanic island of the Tongan archipelago on Friday, January 14, 2022

JTJoao TomeJoao Tome·January 19, 2022SRE & Ops
Engineering — A Workers optimization that reduces your bill

A Workers optimization that reduces your bill

Recently, we made an optimization to the Cloudflare Workers runtime which reduces the amount of time Workers need to spend in memory. We're passing the savings on to you for all your Unbound Workers

KVKenton Varda, ErwinKenton Varda, Erwin·January 14, 2022Engineering
Security — DDoS Attack Trends for Q4 2021

DDoS Attack Trends for Q4 2021

In Q4, we observed a 95% increase in L3/4 DDoS attacks and record-breaking levels of Ransom DDoS attacks. The Manufacturing industry was the most targeted alongside a 5,800% increase in SNMP-based DDoS attacks and massive campaigns against VoIP providers around the world

OVOmer, VivekOmer, Vivek·January 10, 2022Security