Home / Companies / Cloudflare / Blog / January 2017

January 2017 Summaries

6 posts from Cloudflare

Filter
Month: Year:
Post Summaries Back to Blog
On January 30, 2017, Cloudflare introduced a new product called Firebolt to make web ads secure, fast and safe. With Firebolt, ad networks can speed up and secure their ads, resulting in better conversion rates and improved consumer experience. The product delivers lightning-fast ad delivery through Cloudflare's global network of data centers, free simple SSL, support for AMP for Ads, cryptographically signed ads, and advanced browser security features. Firebolt benefits everyone in the ad ecosystem, including consumers, ad networks, and publishers.
Jan 30, 2017 490 words in the original blog post.
In 2017, over half of the traffic to Cloudflare's network was expected to come from mobile devices. However, the mobile web is slower than native apps due to its reliance on traditional web protocols and technologies designed for desktops. Google introduced Accelerated Mobile Pages (AMP) in 2015 to address this issue, with over 600 million AMP pages across 700,000 domains available today. Cloudflare's Accelerated Mobile Links helps improve mobile web speed by automatically identifying links on a site to content with an AMP version and loading it instantly when clicked from a mobile device. This feature increases user engagement as AMP content is loaded in a viewer directly on the linked site, allowing readers to return to the original source after consumption. Cloudflare now powers the only compliant non-Google AMP cache, offering features such as customizable domain for large publishers and working with Google to develop updates addressing concerns about AMP. Accelerated Mobile Links is available to all Cloudflare customers for free.
Jan 12, 2017 749 words in the original blog post.
Cloudflare's Token Authentication feature allows customers to implement access control via URL tokens or HTTP request headers without building complex back-end systems. The edge network checks these tokens before any request is relayed to an origin server, blocking invalid requests and preventing malicious users from reaching the origin. This solution provides benefits such as reduced load on API servers, protection against CSFR attacks, and selective access to third party applications. Token Authentication can be used for both content access control and API protection, with customizable JSON responses for API endpoints.
Jan 10, 2017 1,247 words in the original blog post.
On January 10, 2017, Cloudflare published its seventh transparency report covering the second half of 2016. For the first time, they were able to present information on a previously undisclosed National Security Letter (NSL) received in 2013. An NSL is an administrative subpoena issued by the U.S. federal government for national security purposes without prior judicial approval. Typically, it contains a nondisclosure requirement preventing the recipient from disclosing that the FBI requested information. In this case, Cloudflare objected to the NSL and sought legal assistance from the Electronic Frontier Foundation. The FBI rescinded the NSL in July 2013 but kept the gag order until recently. With the removal of the gag order, Cloudflare can now share more accurate transparency reports with its customers and constituents, allowing for a more informed public policy debate on matters related to electronic communications and national security.
Jan 10, 2017 698 words in the original blog post.
The text discusses an unusual occurrence observed by Marek Majkowski and his team while monitoring their network using Grafana dashboards. They noticed multiple spikes in the number of HTTP requests per second handled by their systems globally, reaching up to 1M requests per second. These spikes were generated by IP addresses from all around the world, with a bias towards South America and North Africa. The traffic was enormous, but the payloads sent to the HTTP servers appeared to be random binary junk rather than typical HTTP request attacks. The bots responsible for these spikes seemed to rotate IP addresses aggressively, resulting in 1.2M unique IP addresses during the 16 spikes happening over 24 hours. The exact cause of these spikes remains uncertain, with possibilities including an attack intended to break their HTTP servers or legitimate connection attempts by some weird, obfuscated protocol.
Jan 09, 2017 1,544 words in the original blog post.
On January 1, 2017, a negative value in Cloudflare's custom RRDNS software caused some DNS resolutions to fail for customers using CNAME records. The issue affected approximately 0.2% of DNS queries and less than 1% of HTTP requests during the outage. The problem was quickly identified and fixed within 90 minutes, with a global rollout by 6:45 UTC. The root cause of the bug was the belief that time cannot go backwards, which led to negative values being recorded in server selection code. Cloudflare has since inspected all its code for other leap second-sensitive uses of time intervals and apologized for any inconvenience caused to customers.
Jan 01, 2017 1,044 words in the original blog post.