October 2017 Summaries
14 posts from Cloudflare
Filter
Month:
Year:
Post Summaries
Back to Blog
Brady Gentile from Cloudflare's product team has written an App Developer Playbook embedded within the developer documentation page. The playbook provides clear ways for app developers to approach promotional strategies, including sharing with online communities like HackerNews, Product Hunt, or reddit; optimizing apps for discoverability; promoting through personal properties; spreading word to existing users; and forming a presence on social media. Additionally, blogging about the app's features and benefits can help increase exposure.
Oct 27, 2017
1,358 words in the original blog post.
Cloudflare has partnered with Google Cloud Platform (GCP) to provide deep insights into customers' domain web traffic. The collaboration offers an end-to-end solution that allows users to retrieve and process access logs in a simple way using GCP components such as Google Storage, Cloud Function, BigQuery, and Data Studio. This solution helps customers adjust their settings, manage costs and resources, and plan for expansion. It also addresses the challenges of storing and processing large volumes of data within short time periods while avoiding high costs. Customers can obtain and process data from Cloudflare access logs on demand or on a regular basis. Google is offering a $500 credit towards a new GCP account to help users get started with this solution.
Oct 26, 2017
542 words in the original blog post.
In October 2017, Andrew Fitch highlighted Spotify as a launch partner for Cloudflare Apps, which allows developers to leverage Cloudflare's global network of websites and applications. Spotify has open-sourced the code to their Cloudflare App, enabling users to easily embed the Spotify player onto their website without needing to copy or paste anything. The app is beneficial for musicians, game creators, activewear companies, and other web properties looking to increase user engagement by adding Spotify widgets and play buttons to their sites. Users can customize the appearance of these elements and link them to any song, album, or playlist in Spotify's music catalog. The Cloudflare App creator allows developers to preview the app on their site without making any changes to their code. Additionally, Spotify has made its code available on GitHub for other developers to clone and fork, providing a starting point for developing Cloudflare Apps.
Oct 25, 2017
556 words in the original blog post.
The author has a unique keyboard setup where they type in Dvorak but use Qwerty for hotkeys, as the classic text-editing shortcuts are optimally located for Qwerty. However, this setup broke when their machine updated to Wayland due to its sensible security rules preventing random programs from capturing all keyboard events. To resolve this issue, they discovered SystemTap, a tool designed for debugging purposes that allows probing the Linux kernel and modifying variables in a running kernel. They used SystemTap to monkey-patch their system, enabling them to get the desired keyboard behavior without maintaining a fork forever or spending weeks developing a feature worthy of pushing upstream. The author proposes two rules for monkey patching: only the exclusive owner of the environment may monkey-patch it and the owner takes full responsibility for any breakages caused.
Oct 24, 2017
1,409 words in the original blog post.
The text discusses the different ways of designing a TCP server with regard to performance, focusing on three models: (a) Single listen socket, single worker process; (b) Single listen socket, multiple worker processes; and (c) Multiple worker processes, each with separate listen socket. It explains that while increasing the number of worker processes can overcome a single CPU core bottleneck, it also opens up new problems. The text then delves into the issue of spreading accept() load across multiple processes and how Linux handles this differently in both cases. Finally, it discusses how SO_REUSEPORT can be used to work around the balancing problem by splitting incoming connections into multiple separate accept queues, resulting in better load distribution. However, it also highlights that while the average is comparable, the maximum value significantly increased and most importantly the deviation is now gigantic, leading to a degraded-latency state. The text concludes by suggesting that changing the standard epoll behavior from LIFO to FIFO could be a better solution.
Oct 23, 2017
1,663 words in the original blog post.
A blog post discusses the KRACK attack that exploits a vulnerability in WPA2 encryption protocol used by modern Wi-Fi networks, allowing interception of traffic. It highlights the importance of HTTPS for secure internet connections and explains how it works with various standards like SSL and TLS. The post also covers HTTP Strict Transport Security (HSTS) to enforce HTTPS usage and HSTS Preload Lists to hardcode a list of websites that need to be connected using HTTPS-only. Despite these measures, there are still potential attack vectors within HTTPS specifications and ciphers. The author recommends implementing technologies like HSTS and submitting sites to preload lists for improved internet security.
Oct 20, 2017
2,133 words in the original blog post.
Laurence Tratt, a programmer and Reader in Software Development at King's College London, discusses the complexity of advanced VMs with Just-In-Time (JIT) compilers. These VMs observe a program's run-time behavior to compile frequently executed parts into machine code, leading to significant speed-ups. However, they are internally complex and can have deoptimization bugs. Tratt's research group at King's College London has received funding from Cloudflare to improve LuaJIT's performance. The team will leverage their expertise in VM work and benchmarking to test hypotheses about heuristic interactions and the importance of rigorous pre- and post-change benchmarking. They aim not only to improve LuaJIT but also contribute to broader research on understanding how VM performance can be improved, potentially influencing future generations of VMs.
Oct 19, 2017
1,355 words in the original blog post.
The Grace Hopper Celebration conference stood out for its exceptional scale and quality of attendees, featuring more than 12,000 participants from all over the world. Over three days, Cloudflare conducted numerous interviews and attracted a large number of visitors to their booth. The event offered a diverse range of talks covering various topics in technology and provided an opportunity for companies like Cloudflare to interact with talented women in tech. The conference's atmosphere was inspiring, making the issue of female representation in the workforce seem more achievable.
Oct 13, 2017
602 words in the original blog post.
On October 12, 2017, a meetup was held at the Cloudflare London office. Ivan Rustic from Hardenize was the guest speaker and demonstrated how they developed a Cloudflare App to promote a culture of security. The event also included talks on the architecture of the Cloudflare network and building and monetizing Cloudflare Apps. Videos of all three talks are available in this blog post. The Cloudflare Apps platform allows developers to deploy their code across the 6 million websites on the Cloudflare network, with fast previewing and deployment capabilities. To stay updated on local events or request a meetup or workshop in your city, join the Meetup groups in San Francisco, Austin, or London, or contact [email protected].
Oct 12, 2017
336 words in the original blog post.
The text discusses a webinar on cloud security and migration, focusing on the experiences of LUSH, an e-commerce cosmetic retailer that migrated from its previous cloud provider to Google Cloud Platform (GCP) in less than three weeks. Trey Guinn, Head of Solutions Engineering at Cloudflare, highlights how companies should approach security during and after migration. He also performs a live demo on setting up Cloudflare load balancing across cloud providers, as well as optimizing security through web application firewall (WAF), SSL / TLS Encryption, and Rate Limiting. The text emphasizes the importance of SSL certificates and provides best practices for their implementation. It also discusses DDoS protection and SQL injection prevention.
Oct 06, 2017
4,045 words in the original blog post.
Cloudflare has launched its newest data center in Zagreb, Croatia, expanding its global network to 118 cities across 58 countries. The company's Europe network now spans 33 cities across 25 countries with plans for ten more. This expansion aims to improve the security and performance of over 6 million Internet properties using Cloudflare for visitors from Croatia and the region, reducing latency as they get closer to their goal of being within 10ms of 99% of the world's population.
Oct 03, 2017
307 words in the original blog post.
On October 3, 2017 at 11:00AM, Dani Grant announced that Ubuntu users are participating in a round trip and encouraged everyone to visit them at GHC (Grace Hopper Celebration). They mentioned meeting up with GNU faces and provided assistance for recharging and Wi-Fi. A breakfast bash was also planned on Thursday morning with Zendesk, featuring various refreshments. Dani Grant will be speaking about encryption and updates for IoT at 1:30PM on Wednesday in OCCC W414. The location of the Ubuntu booth can be found by looking for women wearing capes near other booths with a lava lamp stack, and she is the one with cURLs.
Oct 03, 2017
173 words in the original blog post.
On October 1st, 2017 at 6:00 PM, Ryan Djurovich from Cloudflare shared that they extensively use Go programming language for building a better internet. Created by Google in 2007 and open-sourced in 2009, Go has recently entered the top 10 programming languages on TIOBE Index. To promote its usage internally, Cloudflare launched an internal monthly Go Hack Night at their San Francisco office, which is open to all employees regardless of their department or position. The inaugural event had over 30 attendees, with 26% being completely new to programming and 61% having experience in other languages but new to Go. Every attendee reported learning something from the event. Cloudflare actively encourages an inclusive learning culture and is excited about making the Go programming language more accessible to their entire company. They are currently hiring for positions involving work with Go.
Oct 01, 2017
222 words in the original blog post.
October marks European Cybersecurity Month, an annual campaign aimed at raising awareness of cyber risks among citizens and businesses, and promoting best practices in cybersecurity. This year's campaign was launched in Estonia, a country known for its high level of digital savviness. The EU has announced several initiatives to enhance its cybersecurity capacity and response to cyber attacks, while laying the foundations for increased cyber awareness and better cyber hygiene overall. These proposals range from educational initiatives to investment in research projects and public-private partnerships where technology in cybersecurity and industrial capabilities are developed. Cybersecurity is a common societal challenge that should involve multiple layers of stakeholders, including industry, government, and individuals.
Oct 01, 2017
685 words in the original blog post.