May 2015 Summaries
7 posts from Cloudflare
Filter
Month:
Year:
Post Summaries
Back to Blog
On May 20th, a group of researchers from INRIA, Microsoft Research, Johns Hopkins University, the University of Michigan, and the University of Pennsylvania published an analysis of the Diffie-Hellman algorithm as used in TLS and other protocols. The research includes a novel downgrade attack against the TLS protocol called Logjam, which exploits EXPORT cryptography (similar to FREAK). CloudFlare customers are not affected by this vulnerability since they do not support non-EC Diffie-Hellman ciphersuites on either the client or origin side. The researchers found that 8.4% of Alexa Top Million HTTPS websites were initially vulnerable, with 82% and 10% of them using the same two parameter sets, making precomputation more viable. Both the client and the server need to be vulnerable for the attack to succeed.
May 21, 2015
1,712 words in the original blog post.
On May 21, 2015, Maria Karaivanova announced a new partnership between CloudFlare and Acquia. The collaboration led to the development of Acquia Cloud Edge powered by CloudFlare, which offers web performance and security solutions for Acquia's customers. This product family includes Edge Protect, which defends against DDoS attacks, and Edge CDN, which accelerates content delivery through a global network. The partnership aims to provide the best web performance and security for Drupal-based websites.
May 21, 2015
305 words in the original blog post.
On May 13, 2015, the U.S. House of Representatives passed the USA FREEDOM Act, which aims to end bulk collection and mass surveillance programs by the National Security Agency (NSA). The Act also seeks to increase transparency of the secret Foreign Intelligence Surveillance Court (FISA) and allow companies more freedom in reporting related to FISA orders. CloudFlare supports the passage of this Act, as it believes that mass surveillance programs are unconstitutional and ineffective. The company has joined with other tech policy organizations and companies to advocate for the Act's passage, which is a step towards ensuring national security under the rule of law.
May 13, 2015
383 words in the original blog post.
Marek Majkowski shares a collection of interesting questions about TCP/IP, aiming to encourage readers to review the protocols and spread knowledge about them. The questions cover topics such as lowest TCP port number, URG pointer field usage, RST packet payload, IPv6 flow field usage, IP_FREEBIND socket option, PSH flag functionality, SYN cookies, UDP checksum field, TCP simultaneous open, stupid window syndrome, CWE and ECE flags in TCP header, IP ID field and DF bit, ICMP Path MTU, Linux sysctl settings, incoming TCP connections handling, BGP bogons, MD5 checksums in packets, and differences in checksumming algorithms between IPv4 and IPv6.
May 11, 2015
537 words in the original blog post.
Google has announced that its hosted PageSpeed Service will be shut down on August 3, 2015. Users of this service need to move their websites elsewhere before the deadline to avoid any disruption. Google is inviting these users to migrate their sites to CloudFlare for global acceleration and additional benefits. While both services aim at speeding up webpages, CloudFlare offers more performance gains through a global network footprint, Railgun for dynamic content acceleration, built-in SPDY support, and other features. Additionally, CloudFlare also provides security, SSL, DNS, and more across all plans, including the free tier. The migration process from PageSpeed Service to CloudFlare is simple and does not require any software installation or changes to the host.
May 08, 2015
244 words in the original blog post.
The text discusses how CloudFlare uses the programming language Go extensively and has developed assembly implementations of Elliptic Curves and AES-GCM for improved cryptographic performance on amd64 architecture. These improvements bring the performance up to par with OpenSSL, which is used by CloudFlare for Universal SSL. The fork includes constant-time and side-channel protected implementations, as well as small improvements to Go's RSA implementation. AES-GCM is an Authenticated Encryption with Associated Data (AEAD) that combines a cipher and a MAC algorithm into a single robust algorithm using a single key. By supporting the two state-of-the-art AEADs - AES-GCM and ChaCha20-Poly1305, together with ECDSA and ECDH algorithms, CloudFlare can provide the fastest, most flexible, and most secure TLS experience possible on all platforms.
May 07, 2015
1,053 words in the original blog post.
CloudFlare has redesigned its original interface to improve user experience and accommodate a growing variety of users and devices. The new dashboard features a versatile, scalable, and consistent design that includes apps, modules, inline help content, and responsive design for seamless use across different devices. The redesign also aligns with the company's evolving brand identity and sets the stage for future feature updates and UI improvements.
May 01, 2015
953 words in the original blog post.