May 2017 Summaries
17 posts from Cloudflare
Filter
Month:
Year:
Post Summaries
Back to Blog
Cloudflare has received an overwhelming response to its blog posts on patent trolls and its program for finding prior art on Blackbird Tech patents, dubbed Project Jengo. The company is significantly expanding the program and has received $50,000 from an anonymous benefactor to help invalidate all of Blackbird Tech's patents. Cloudflare aims to find prior art on 100% of the Blackbird Tech patents and will update a chart as they review submissions. The company is also working with lawmakers in Illinois, Massachusetts, and Delaware to advance new laws that limit the practices of patent trolls, including Blackbird Tech's "new model."
May 25, 2017
2,708 words in the original blog post.
Cloudflare has announced that it will be enabling IPv6 by default for all its free domains starting from May 25th, 2017. The company aims to move away from the legacy world of IPv4-only and embrace the modern era where both IPv4 and IPv6 are treated equally. Cloudflare has been a gateway for visitors on IPv6 connections to access sites and applications hosted on legacy IPv4-only infrastructure, and with this change, it is making IPv6 always on, with no off-switch. The company is also working alongside OpenDNS to make IPv6 even faster and more globally deployed by prototyping a new idea - returning all available addresses in one DNS query. This will reduce the number of necessary round trips in half and pre-populate global DNS caches with IPv6 addresses, making IPv6 lookups faster in the future.
May 25, 2017
929 words in the original blog post.
In this blog post, the author discusses popular reflection attacks and how to defend against them. Reflection attacks involve a server capable of IP address spoofing, a protocol vulnerable to reflection/amplification, a list of reflectors, and a victim IP address. The attacker sends fake UDP requests with the victim's IP address in the source IP address field, causing the reflector server to send responses to the victim.
The author provides statistics on three popular reflection attack vectors: NTP, SSDP, and DNS. They explain how Cloudflare mitigates these attacks using their Anycast network and firewall rules. The post also touches upon other protocols used in reflection attacks and emphasizes the importance of proper internet hygiene and sufficient network capacity to combat such threats.
May 24, 2017
2,832 words in the original blog post.
Cloudflare has launched Argo, a "virtual backbone" for the modern Internet that analyzes and optimizes routing decisions across the global network in real-time. Similar to Waze's route optimization feature for automobiles, Argo can efficiently route connections by avoiding packet loss, congestion, and outages. The results are impressive: an average 35% decrease in latency, a 27% decrease in connection errors, and a 60% decrease in cache misses. Argo is priced at $5/domain monthly, plus $0.10 per GB of transfer from Cloudflare to your visitors.
May 18, 2017
1,286 words in the original blog post.
On May 14, 2017, Cloudflare announced the expansion of its Load Balancing service to all customers. This feature helps avoid website downtime caused by unreliable hosting providers, internet outages, or servers. The Cloudflare Load Balancer automatically sends notifications when things fail and come back up again. It can withstand traffic volumes that smaller providers, virtual machines, or hardware appliances cannot handle due to its experience dealing with large DDoS attacks. This also allows users to avoid business-impacting downtime when major cloud compute providers have issues. The Load Balancer provides near instant failover for proxied traffic and actively monitors traffic to alert customers of any site issues. Pricing starts at $5 per month, including 500,000 DNS queries each month.
May 14, 2017
614 words in the original blog post.
On May 12, 2017, Cloudflare announced new data center deployments in Detroit and San Diego, bringing their total to 115 locations worldwide across 57 countries. These additions join Colombo, Sri Lanka, and Cape Town, South Africa as the latest cities to be included in Cloudflare's global network expansion. The company now serves customer traffic from 26 North American cities, including 22 in the United States alone. Detroit and San Diego are strategically located near international borders with Canada and Mexico respectively, offering unique opportunities for regional interconnection projects such as DET-IX. Cloudflare plans to continue expanding its network until it is within milliseconds of every internet user worldwide.
May 12, 2017
347 words in the original blog post.
Cloudflare has been sued by patent troll, Blackbird Technologies, and is seeking help from the public in combating such legal threats. The company is offering up to $50,000 for prior art that can be used to invalidate patents held by Blackbird Tech. This initiative aims to expose weaknesses in these patents and prevent them from being weaponized against innovative companies. Prior art refers to evidence showing the technology was in use or known before the patent holder conceived of it. Awards will be given based on relevance and usefulness, with a total of $20,000 for prior art related to the '335 patent used by Blackbird against Cloudflare, and up to $30,000 for other patents held by the company. The public can submit their suggestions through cloudflare.com/priorartsearch/.
May 11, 2017
1,110 words in the original blog post.
On March 20th, Cloudflare received its first patent infringement claim from Blackbird Tech LLC. The company is responding by filing an answer to the claim in a federal court in Delaware and plans to contest the lawsuit vigorously. They also plan to fund an award for a crowdsourced search for prior art that can be used to invalidate Blackbird patents, and ask relevant bar associations to investigate potential violations of rules of professional conduct by Blackbird and its attorneys. Cloudflare is against patent trolls like Blackbird Technologies, which they believe distort the judicial system and exploit inventors for their own gain.
May 11, 2017
4,431 words in the original blog post.
On May 11, 2017, Cloudflare opened its second data center in South Africa, located in Cape Town. This expansion follows the company's first data center in Africa, which was established in Johannesburg back in December 2014. The new data center is expected to improve internet performance and reduce latency for millions of users in the region. With this addition, Cloudflare now operates six data centers across Africa, including facilities in Cairo, Luanda, Mombasa, Djibouti, Johannesburg, and Cape Town.
May 11, 2017
407 words in the original blog post.
The text discusses the implementation of DNS analytics for all Cloudflare customers due to its massive scale. It outlines how logs are processed from the edge using structured log messages in Cap'n Proto format, Apache Kafka clusters, and stream processors generating aggregations. The author also explains why they chose not to store full DNS message payloads and instead logged only telemetry data such as response code, size, or query name. Furthermore, it details the use of ClickHouse for storing logs and how it handles data storage and indexing. It also discusses the integration with Superset and Grafana for visualization purposes and mentions that these tools are available in users' Cloudflare dashboards analytics. The text concludes by encouraging interested individuals to apply for positions at Cloudflare.
May 10, 2017
2,441 words in the original blog post.
On May 9th, 2017, Cloudflare announced the addition of four new data centers to its network. The first of these is located in Colombo, Sri Lanka, marking their 112th global data center and 38th in Asia. This expansion will significantly improve internet performance for six million properties using Cloudflare across Sri Lanka. Previously, users were served from Singapore or Dubai data centers. The country has experienced a surge of over one million new internet users in the past year alone, with room for further growth at its current 30% internet penetration rate. Further deployment details are expected to be revealed later that week, which will provide additional redundancy to existing facilities in North America and Africa. Cloudflare also encourages interested individuals to join their team in building one of the world's largest networks.
May 09, 2017
154 words in the original blog post.
On May 7, 2017, Matthew Prince, CEO of Cloudflare, addressed feedback from an article published by ProPublica that criticized the company's handling of abuse reports. As a result, they decided to update their abuse reporting system to allow anonymous reporting for threats and child sexual abuse material. The changes are expected to be implemented by the end of the week. Prince explained Cloudflare's role as a network provider rather than a hosting provider and discussed how their abuse handling policy has evolved over time. He acknowledged that they had made mistakes in the past but were committed to improving their processes. The company remains firm on its belief that it is not their role to make determinations on what content should be online, leaving those decisions to law enforcement, legislatures, and courts.
May 07, 2017
1,781 words in the original blog post.
On May 5th, 2017, a new feature was introduced in the Cloudflare analytics dashboard - detailed DNS analytics for domains. The DNS analytics dashboard provides insights into DNS traffic health, including response codes and NXDOMAIN queries. Enterprise customers can filter the dashboard by hostname or record type. Additionally, users can build their own dashboards using a Grafana plugin and an API that provides extra information like query distribution over IPv6 vs IPv4 and UDP vs TCP. DNS Firewall customers will soon have access to a new dashboard showing latency and errors on a per-origin basis.
May 05, 2017
675 words in the original blog post.
On May 3, 2017, Cloudflare launched a new Community platform at community.cloudflare.com to provide users with a centralized location for discussing all things related to the company's services. The community is open to anyone who uses Cloudflare, regardless of their experience level or domain management method. Users can access the forum by signing in with their Cloudflare account and going through an email verification process. The platform features broad categories such as Performance, Security, Product Feedback, and a Meta category for suggestions about the Community itself.
May 03, 2017
483 words in the original blog post.
The eero Home WiFi System uses multiple access points and TrueMesh technology to provide consistent, stable WiFi coverage throughout a home. To ensure high availability and performance of its infrastructure, eero relies on Cloudflare for CDN, security, and high availability services. Eero devices continuously communicate with the cloud, sending device diagnostic data and supporting features in their mobile application. By using Cloudflare as a secondary internet check, eero can test internet availability from every device while maintaining privacy and low costs. This collaboration helps both companies think about specific needs of IoT products and build out features that support scale across millions of devices.
May 03, 2017
649 words in the original blog post.
The blog post discusses four anti-patterns in Internet of Things (IoT) devices that pose significant security risks. Firstly, the HTTP Pub/Sub pattern can be exploited to create a DDoS vulnerability as it does not validate if the receiver of the subscribed message wants the message or not. Secondly, running IoT devices themselves as TLS servers with self-signed server-side certificates can fail to maintain trust relationships and pose severe security risks. Thirdly, unencrypted bootloaders on IoT devices can expose sensitive data in memory when physical theft occurs. Lastly, directly connecting IoT devices to a database server for pushing data can lead to performance difficulties due to lock contention and polling databases for changes. The post suggests using message broker services exposed by HTTP APIs as a solution to these anti-patterns.
May 02, 2017
1,095 words in the original blog post.
Cloudflare now offers TLS with client authentication to enterprise customers, adding an extra layer of security by authenticating the client connecting to a server. This feature is particularly useful in scenarios involving IoT devices or mobile apps with millions of installs exchanging secure information. Unlike API keys, client certificates offer enhanced security as their private key is used to create a digital signature in every TLS connection, preventing new requests from being instantiated if the certificate is compromised mid-connection. Cloudflare's edge can be utilized for offloading the CPU-intensive verification process of TLS Client Authentication. The company plans to add support for this feature across all its plans within a year.
May 01, 2017
756 words in the original blog post.