Home/Cloudflare
Source

Cloudflare

2,113 articles from Cloudflare.

Security — Securing Cloudflare Using Cloudflare

Securing Cloudflare Using Cloudflare

Cloudflare is committed to bolstering our security posture with best-in-class solutions — which is why we often turn to our own products as any other Cloudflare customer would.

MEMolly, Evan JohnsonMolly, Evan Johnson·March 18, 2022Security
Networking — Cloudflare Observability

Cloudflare Observability

Being a single pane of glass for all network activity has always been one of Cloudflare’s goals. Today, we’re outlining the future vision for Cloudflare observability.

TNTanushree, NatashaTanushree, Natasha·March 18, 2022Networking
Networking — Introducing SSH command logging

Introducing SSH command logging

We built SSH command logging into Cloudflare Zero Trust to provide SSH visibility at a network layer instead of relying on software on individual machines

CCloudflare·March 18, 2022Networking
Networking — Packet captures at the edge

Packet captures at the edge

Today, we’re excited to announce the general availability of on-demand packet captures from Cloudflare’s global network

ANAnnika, NadinAnnika, Nadin·March 17, 2022Networking
AI & ML — Improving the WAF with Machine Learning

Improving the WAF with Machine Learning

Today we are excited to complement managed rulesets (such as OWASP and Cloudflare Managed) with a new tool aimed at identifying bypasses and malicious payloads without human involvement, and before they are exploited

CCloudflare·March 15, 2022AI & ML
Security — A new WAF experience

A new WAF experience

The security landscape is moving fast. We invited users to help us shape a new WAF experience that enables us to evolve WAF to meet their demands and use cases

XMXmflsct, MruXmflsct, Mru·March 15, 2022Security
Engineering — Cloudflare Zaraz supports CSP

Cloudflare Zaraz supports CSP

If you have Cloudflare Zaraz enabled on your website, you don’t have to ask yourself twice if you should enable CSP because there’s no harmful collision between CSP & Cloudflare Zaraz

SBSimona BadoiuSimona Badoiu·March 15, 2022Engineering
Security — Investigating threats using the Cloudflare Security Center

Investigating threats using the Cloudflare Security Center

The data we glean from attacks trains our machine learning models and improves the efficacy of our network and application security products, but historically hasn’t been available to query directly. This week, we’re changing that

PJPatrick, JessePatrick, Jesse·March 14, 2022Security
Engineering — Introducing: Backup Certificates

Introducing: Backup Certificates

We are excited to introduce backup certificates to increase reliability of our service for anyone using the Cloudflare platform in the event of key compromises or related issues

DDinaDina·March 14, 2022Engineering
SRE & Ops — Get full observability into your Cloudflare logs with New Relic

Get full observability into your Cloudflare logs with New Relic

Correlating Cloudflare logs across your stack in New Relic One is powerful for monitoring and debugging in order to keep services safe and reliable. We’re excited to have partnered with New Relic to create a direct integration that provides this visibility

TMTanushree, Mike Neville O NeillTanushree, Mike Neville O Neill·March 14, 2022SRE & Ops
Security — Welcome to Security Week 2022!

Welcome to Security Week 2022!

Welcome to our first innovation week of the year: Security Week! In this post we will be going over Cloudflare’s security products’ history giving you an introduction to all the great announcements we have planned

MTMichael TremanteMichael Tremante·March 13, 2022Security
Engineering — International Women’s Day 2022

International Women’s Day 2022

Welcome to International Women’s Day 2022! Here at Cloudflare, we are happy to celebrate it with you! Our celebration is not only this blog post, but many events prepared for the month of March: our way of honoring Women’s History Month by showcasing women’s empowerment

SASofia, AngelaSofia, Angela·March 8, 2022Engineering
Networking — Announcing experimental DDR in 1.1.1.1

Announcing experimental DDR in 1.1.1.1

The majority of DNS queries on the Internet today are unencrypted. This post describes a new protocol, called Discovery of Designated Resolvers (DDR), that allows clients to upgrade from unencrypted DNS to encrypted DNS when only the IP address of a resolver is known.

CAChristopher, AnbangChristopher, Anbang·March 8, 2022Networking
Security — HPKE: Standardizing public-key encryption (finally!)

HPKE: Standardizing public-key encryption (finally!)

HPKE (RFC 9180) was made to be simple, reusable, and future-proof by building upon knowledge from prior PKE schemes and software implementations. This article provides an overview of this new standard, going back to discuss its motivation, design goals, and development process

CCloudflare·February 24, 2022Security
Engineering — Building Confidence in Cryptographic Protocols

Building Confidence in Cryptographic Protocols

This blogpost refers to the efforts to use formal/verification/implementation for post-quantum algorithms to achieve better assurance for them. It also touches on our Cloudflare efforts on this

TJThom, Jonathan HoylandThom, Jonathan Hoyland·February 24, 2022Engineering
Engineering — Making protocols post-quantum

Making protocols post-quantum

Post-quantum key exchange and signature algorithms come with different trade-offs that we’re familiar. How do we handle that when updating protocols, is this an opportunity to revisit the status quo?

CCloudflare·February 23, 2022Engineering
Security — BGP security and confirmation biases

BGP security and confirmation biases

On February 1, 2022, a configuration error on one of our routers caused a route leak of up to 2,000 Internet prefixes to one of our Internet transit providers. This leak lasted for 32 seconds and at a later time 7 seconds

CCloudflare·February 23, 2022Security
Engineering — Deep dive into a post-quantum signature scheme

Deep dive into a post-quantum signature scheme

How can one attest to an identity and prove it belongs to one self? And how can one do it in the face of quantum computers? In this blog post, we examine these questions and explain what post-quantum signatures are

GTGoutam Tamvada, SofiaGoutam Tamvada, Sofia·February 22, 2022Engineering
SRE & Ops — Internet is back in Tonga after 38 days of outage

Internet is back in Tonga after 38 days of outage

Tonga, the South Pacific archipelago nation (with 169 islands), was reconnected to the Internet this early morning (UTC) and is back online after successful repairs to the undersea cable that was damaged on Saturday, January 15, 2022, by the January 14, volcanic eruption

JTJoao TomeJoao Tome·February 22, 2022SRE & Ops
Engineering — The post-quantum state: a taxonomy of challenges

The post-quantum state: a taxonomy of challenges

At Cloudflare, we strive to help build a better Internet, which means a quantum-protected one. In this post, we look at the challenges for migrating to post-quantum cryptography and what lies ahead using a taxonomy

SSofiaSofia·February 21, 2022Engineering
Engineering — The quantum solace and spectre

The quantum solace and spectre

What is quantum computing and what advances have been made so far on this front? In this blog post, we will answer this question and see how to protect against quantum adversaries

CCloudflare·February 21, 2022Engineering
Security — Adding a CASB to Cloudflare Zero Trust

Adding a CASB to Cloudflare Zero Trust

Earlier today, Cloudflare announced that we have acquired Vectrix, a cloud-access security broker (CASB) company focused on solving the problem of control and visibility in the SaaS applications and public cloud providers that your team uses

SJSam, John Graham CummingSam, John Graham Cumming·February 10, 2022Security
Engineering — Happy Data Privacy Day!

Happy Data Privacy Day!

On this Data Privacy Day, we look back at how events in 2021 shaped the privacy world, and we look ahead to what 2022 may have in store

CCloudflare·January 28, 2022Engineering