December 2022 Summaries
42 posts from Cloudflare
Filter
Month:
Year:
Post Summaries
Back to Blog
In 2022, there were significant updates and advancements made in the Hypertext Transfer Protocol (HTTP), an essential communication protocol used on the web. These developments ranged from new security features to improvements in intermediation capabilities. Some of the key highlights included:
1. Intermediation-focused work: The MASQUE Working Group enabled more efficient tunneling, while Oblivious HTTP added privacy protection layers for users.
2. Privacy Pass adoption: This authentication scheme was widely deployed by Apple to protect user data and improve their browsing experience.
The future of HTTP development in 2023 may involve improvements to existing header structures, better testing infrastructure, and potential support for real-time communication protocols such as WebSockets or WebTransport. Overall, the continuous evolution of HTTP ensures that it remains compatible with the ever-growing digital landscape while addressing emerging security and privacy concerns.
Dec 30, 2022
1,998 words in the original blog post.
HTTP, a foundation of the web and one of the Internet's most popular protocols, has been successful due to factors such as familiarity, availability of implementations, ease of use, reuse of existing mechanisms, presence in target deployments, and ability to traverse firewalls. The community working on HTTP actively maintains and develops the protocol to ensure interoperability and meet modern needs. In 2022, significant developments included the publication of HTTP/3, which uses QUIC as a replacement for TCP; deployment of Early Hints, an alternative to server push; and advancements in privacy-focused intermediation through MASQUE and OHTTP.
Dec 30, 2022
2,019 words in the original blog post.
The year 2022 saw a rise in cyber attacks across various locations. Technology sites consistently faced the largest percentage of mitigated requests globally, with peaks in April, July/August, and late November. Target categories for these attacks varied widely, with no one region being more vulnerable than others. Internet service providers need to improve support for IPv6 as available IPv4 address space becomes increasingly scarce. Finally, the United States was identified as the top source of phishing emails observed by Cloudflare Area 1 Email Security during 2022.
The full findings from our "year in review" can be explored at: https://radar.cloudflare.com/2022-year-in-review/index.html.
Dec 22, 2022
7,856 words in the original blog post.
- In 2022, mobile devices accounted for an average of 80% of global Internet traffic.
- The top five countries with the highest percentage of mobile traffic were Iran, Sudan, Yemen, Oman, and Kuwait.
- IP Reputation, Bot Management, and Access Rules were the most frequently used techniques to address attacks in many locations.
- HTTP Anomaly was the most frequently applied rule when mitigating attacks globally, but Directory Traversal and XSS rules were more commonly used in some countries.
- Technology sites consistently saw around 20% of mitigated traffic through the year from the United Kingdom.
- The United States was the top source of phishing emails observed by Area 1 during 2022, with a total of 23 locations holding a spot in the rankings for at least one month during the year.
Dec 22, 2022
7,921 words in the original blog post.
Starting today, users can add custom comments and tag DNS records on all zone plans through the API and Cloudflare dashboard. This feature helps users understand the purpose of each DNS record and avoid accidentally modifying or deleting important records. Custom tags can be simple keys or key-value pairs. The addition of comments and tags will not impact the resolution or propagation of DNS records, and are only visible to those with access to the zone. Users on Pro, Business, or Enterprise plans can also filter their dashboard for specific comments, tags, names, types, content, or proxy status. The DNS record table width has been increased for better visibility.
Dec 21, 2022
993 words in the original blog post.
Blocking by Internet Protocol (IP) addresses is a common method used to restrict access to content online, but doing so can lead to overblocking and inadvertently limiting access to unrelated domains. In this article, we explore the reasons why IP blocking should be avoided and discuss potential solutions. We also share insights about Cloudflare Radar Outage Center
Dec 16, 2022
4,505 words in the original blog post.
Cloudflare is committed to building a better Internet. In this week's blog post series, we share updates and initiatives in areas such as security, privacy, sustainability, policy advocacy, and impact projects that contribute to the creation of a more secure, private, sustainable, and inclusive digital environment for all users.
Throughout the week, we discuss topics like addressing Internet shutdowns with Radar Alerts and API, expanding Project Pangea to connect and
Dec 16, 2022
2,038 words in the original blog post.
Cloudflare emphasizes the significance of public policy engagement in building a better internet. The company's core values are being principled, curious and transparent. They approach public policy by prioritizing issues that have significant impact on their operations or have distinct perspectives compared to other players in the industry. Their team includes individuals with expertise from government, law firms and tech industry which allows them to be involved in important policy conversations about the internet. Cloudflare is not a Political Action Committee (PAC) and does not make political contributions but they are members of several associations and coalitions tracking policy developments worldwide.
Dec 16, 2022
1,115 words in the original blog post.
In a recent post, Andie Goodwin announced the release of Cloudflare's 2022 Impact Report. The report highlights their progress in building a better internet and covers their work on environmental, social, and governance priorities. Key points include showcasing successes from Cloudflare Impact programs, celebrating awards and recognitions, as well as addressing transparency and privacy. The report is organized around three themes: principled, for everyone, and sustainable. Additionally, it serves as a repository for disclosures consistent with commitments to the Global Reporting Initiative (GRI), Sustainability Accounting Standards Board (SASB), and UN Global Compact (UNGC). The full report can be accessed online where users can explore their latest diversity statistics, learn about new employee resource groups, examine emissions data calculations and updates on 2023 plans.
Dec 16, 2022
254 words in the original blog post.
The HBCU Smart Cities Challenge encourages Historically Black Colleges or Universities (HBCUs) in the United States to develop technological solutions for real-world problems. Cloudflare, a cyber security company, supports this initiative by providing mentors and the opportunity to apply for Project Galileo, which offers free cyber security protection. HBCU Smart Cities Challenge aims to address issues like water management, broadband accessibility, public health, and affordable housing in various cities. Students from HBCUs work together to build smart city applications using Internet of Things technology over several months. Cloudflare's involvement in the challenge is a testament to their commitment to bridging the gap in accessibility to digital landscapes for minority communities while ensuring safety and optimizing performance. The initiative also highlights the unique role HBCUs play in closing socioeconomic gaps for Black students, as evidenced by personal experiences of alumni like Nikole Phillips.
Dec 16, 2022
838 words in the original blog post.
In 2021, a new employee resource group (ERG) was launched at my company, focusing on supporting our global community of Iranian employees. The initiative, called Persianflare, aimed to create an inclusive environment where Iranian employees could connect with each other and share their unique experiences and challenges.
The idea for the ERG came from a conversation between myself and another employee who was also of Iranian descent. We were discussing how we both felt isolated at work due to our cultural backgrounds and how it would be great if there was a way for us to connect with other Iranian employees at the company.
After sharing our thoughts with the HR team, they expressed their support for creating an ERG specifically for Iranian employees. They encouraged us to reach out to other Iranian employees in the company and start building a community.
Over the next few months, we began reaching out to other Iranian employees and inviting them to join the new ERG. To our surprise, we received an overwhelmingly positive response from many of our colleagues who were also interested in connecting with others from their cultural background.
As more people joined the group, we started organizing regular virtual events and meetings where Iranian employees could come together to share their experiences, learn from each other, and provide support for one another. We also began collaborating with other ERGs within the company to organize joint events and initiatives aimed at promoting diversity, inclusion, and cultural awareness among all employees.
One of the most impactful initiatives we launched was a mobile app called "Persianflare" that provided resources and support for Iranian immigrants in the United States. The app featured information on topics such as housing, employment, healthcare, and legal rights, as well as a community forum where users could connect with other members and share their experiences.
The launch of the Persianflare app was a huge success and received widespread media coverage, both within the Iranian-American community and beyond. It also generated significant interest from other companies and organizations that were looking for ways to support their own employees who had immigrated to the United States from Iran.
Overall, our experience with launching an ERG for Iranian employees has been incredibly positive and rewarding. We have seen firsthand how important it is for individuals to feel connected with others from their cultural backgrounds, especially in a diverse and global company like ours.
Going forward, we are committed to continuing to support and grow the Persianflare community within our organization, as well as exploring new ways to promote cultural awareness and understanding among all employees. We believe that by fostering an inclusive environment where everyone feels valued and respected, regardless of their background or identity, we can help create a stronger and more successful company for everyone.
Dec 16, 2022
1,925 words in the original blog post.
Cloudflare Radar has been tracking the deployment and effectiveness of Border Gateway Protocol (BGP) Route Origin Validation (ROV), a critical security feature for protecting users from malicious route leaks. The analysis was based on data gathered from October 2022, covering approximately 96.5% of the world's Internet population.
The study estimated that only 6.5% of global Internet users are currently protected by ROV, with Sweden and Bolivia leading the way in adoption. Countries such as Denmark, Greece, Switzerland, Sweden, Australia, Finland, and Chad have already achieved effective coverage above 50%, while the Netherlands and the United States remain below this threshold.
To ensure a comprehensive assessment of ROV deployment, only ASes with an observed drop rate for RPKI-invalid requests greater than or equal to 95% were considered as fully protected. This resulted in a total of 261 million end users currently safe from malicious route leaks. However, there is still much work to be done before the world can declare BGP secure.
Reference(s): https://blog.cloudflare.com/worldwide-rov-deployment/
```
Dec 16, 2022
2,445 words in the original blog post.
Cloudflare has released a new Third Party Code of Conduct that applies to its suppliers, resellers, and other partners. The code covers topics such as human rights, fair labor, environmental sustainability, anti-bribery and anti-corruption, trade compliance, anti-competition, conflicts of interest, data privacy and security, and government contracting. The company aims to ensure that third parties act with ethics and integrity on its behalf by encouraging them to share the same values as Cloudflare. Violations of the code may result in termination of relationships between Cloudflare and third parties.
Dec 16, 2022
653 words in the original blog post.
In late August 2022, an issue with local Austrian Internet Service Providers (ISPs) caused a service disruption that affected thousands of websites in Austria over a two-day period. The court-ordered IP block was intended to block 14 websites that copyright holders argued were violating copyright. However, the blocking of these IP addresses also rendered many other unrelated sites inaccessible. This incident highlights the problematic nature of IP blocking as a method for addressing content online.
IP blocking is a common practice used by governments and ISPs to limit access to certain websites or types of content. However, it often results in collateral damage, where legitimate websites are also blocked due to sharing an IP address with restricted sites. This can have significant consequences for website owners and users who rely on these sites for information or services.
The European Court of Human Rights (ECHR) has ruled that the indiscriminate blocking of websites is impermissible, as it amounts to arbitrary interference with the rights of owners of such websites. Despite this ruling, IP blocking continues to be a widespread practice around the world.
One solution to address the issue of content control without causing collateral damage is to focus on removing or restricting content at its source. This can be achieved through legal mechanisms like the EU's new Digital Services Act or the Digital Millennium Copyright Act, which provide tools for addressing illegal content while respecting important due process principles.
In conclusion, IP blocking is a problematic method for addressing content online, as it often results in unintended consequences and collateral damage. Instead, governments and ISPs should focus on building legal mechanisms that enable the removal or restriction of content at its source, while respecting users' rights to access information and services.
Dec 16, 2022
4,553 words in the original blog post.
Cloudflare has announced its participation in the AS112 project, becoming an operator of this community-operated anycast deployment of DNS servers that primarily answer reverse DNS lookup queries misdirected to the public Internet. The addition of Cloudflare's global network is expected to significantly improve the stability, reliability and performance of this distributed public service. The AS112 project aims to handle reverse DNS lookup queries for private-only use addresses that should never appear in the public DNS system.
Dec 15, 2022
3,220 words in the original blog post.
Cloudflare has introduced an updated version of its Geo Key Manager product, which allows users to define boundaries for storing encryption keys in specific geographic locations. The new version offers more flexibility and supports over 30 countries and regions. It also includes redundancy restrictions to ensure high availability and performance metrics to help customers evaluate the latency impact of their choices. Currently available via API, a user-friendly interface is under development.
Dec 15, 2022
1,525 words in the original blog post.
Cloudflare enables faster, more secure connectivity for users in next-generation markets by bringing its powerful edge network closer to them. Through partnerships with local ISPs and leveraging advancements like 5G, Cloudflare ensures that users get connected to the Internet more quickly while preserving their privacy. Additionally, Cloudflare's developer platform helps developers build high-performance applications specific to these markets. By partnering with network operators in next-generation markets, Cloudflare can help deliver a better user experience and foster innovation for future generations of internet users.
1. Bringing the edge closer: Cloudflare works with local ISPs to bring its powerful edge network closer to users in next-generation markets, enabling faster connectivity and improved performance.
2. 5G support: By leveraging advancements like 5G, Cloudflare ensures that users get connected to the Internet more quickly while preserving their privacy.
3. Edge Partner Program: Through partnerships with local ISPs, Cloudflare helps bring applications closer to users in next-generation markets, ensuring better end-to-end performance.
4. Developer platform: Cloudflare's developer platform allows application developers to build a distributed application that runs right where their users are, so they don't have to choose between performance and cost savings.
5. Fostering innovation: By delivering faster, more secure connectivity for users in next-generation markets, Cloudflare helps foster innovation for future generations of internet users.
By addressing the challenges faced by users in these emerging markets, Cloudflare is helping shape the future of the Internet.
Dec 15, 2022
3,231 words in the original blog post.
Internet Society, Access Now, and Open Observatory of Network Interference (OONI) are among the nonprofit organizations that rely on Cloudflare’s Radar data to track government-mandated shutdowns of the internet. These organizations use a combination of direct observation, local media reports, and information from technical sources like Radar to verify instances of internet blackouts ordered by governments in various countries around the world. The goal is not only to document these incidents accurately but also to raise awareness about their impact on human rights and economic growth.
Reference(s):
https://cloudflare-radar.com/outages/
https://www.internetsociety.org/blog/2023/04/using-cloudflare-radar-to-track-internet-shutdown-incidents/
https://accessnow.org/keepiton/
https://ooni.org/
```
Dec 15, 2022
1,653 words in the original blog post.
Cloudflare's approach to addressing online abuse is based on the principles of proportionality, transparency, and continuous learning. The company strives to strike a balance between protecting users from harmful content while respecting their right to access information freely. In cases where content is deemed illegal or prohibited by law, Cloudflare takes steps to remove it or limit its visibility on the Internet. However, in many cases, the company prefers not to take action against websites that are merely unpopular or controversial.
In addressing abuse online, Cloudflare prioritizes protecting users from harmful content while respecting their right to access information freely.
Dec 15, 2022
3,837 words in the original blog post.
In 2019, Cloudflare launched Bot Fight Mode to deter malicious bots online by redirecting them to a challenge page requiring computationally intensive tasks. The company accounts for the carbon cost of this process by planting trees through its partnership with One Tree Planted. This year, they observed that bot operators are giving up quickly and moving on to other targets due to the increased bill associated with their CPU-intensive challenges. Bot Fight Mode is now busier than ever, issuing six times more CPU intensive challenges per day compared to last year, thanks to a new detection system written using Cloudflare's ruleset engine. In 2023, they plan to give everyone the ability to write their own flexible Bot Fight Mode rules. Additionally, due to the success of Bot Fight Mode, Cloudflare has contributed over 35,000 trees to restoration projects in Nova Scotia and West Bengal, India.
Dec 14, 2022
984 words in the original blog post.
Cloudflare's commitment to sustainability includes reducing its carbon footprint by investing in more energy-efficient infrastructure and hardware systems engineering. The company's goal is to achieve a 100% renewable energy mix for its data centers and operations, which it has achieved across its facilities worldwide. To further reduce its carbon footprint, Cloudflare is leveraging modular hardware systems designs, maximizing power efficiency through testing and deployment of more efficient architectures, and using domain-specific accelerators. Additionally, the company is working towards industry-standard reporting for greenhouse gas emissions in the IT sector, which will help establish a baseline for carbon footprint reduction efforts across the industry.
Dec 14, 2022
2,366 words in the original blog post.
A more sustainable end-of-life for your legacy hardware appliances with Cloudflare and Iron Mountain
Cloudflare has partnered with Iron Mountain to provide sustainable decommissioning and disposal of used hardware appliances for its customers. The partnership offers preferred pricing and discounts to recycle or resell legacy hardware through Iron Mountain's services. By replacing legacy hardware with Cloudflare's network, businesses can benefit from stronger security, better performance, lower operational overhead, and a reduced carbon footprint due to the multi-tenant SaaS approach. When upgrading to new technologies, users have three sustainable disposal options: remarket/reuse, recycle, and destroy. By partnering with Iron Mountain, businesses can streamline their hardware decommissioning process while contributing to environmental sustainability goals.
Dec 14, 2022
1,252 words in the original blog post.
On July 2021, Cloudflare initiated an exploration into reducing the internet's environmental impact, finding that a sustainable Internet is essential. To investigate this, they commissioned Analysys Mason to study the carbon efficiency of network functions provided by them against on-premise solutions. Preliminary findings reveal that Cloudflare's Web Application Firewall (WAF) can reduce carbon emissions by up to 90% compared to on-premise appliances in low-medium traffic demand scenarios. The full report will be available next year, expected to reveal more ways moving to Cloudflare can help reduce your infrastructure’s carbon footprint. This research is a part of the broader plan of addressing the Internet's energy and emissions problem, which contributes around 35% of global greenhouse gas emissions. The study aims to explore efficiency gains in all layers of the network stack as well as the basic architecture of the Internet itself.
Dec 14, 2022
693 words in the original blog post.
Cloudflare has achieved FedRAMP Moderate Authorization for its public sector suite of services, Cloudflare for Government. This demonstrates the company's commitment to customer trust and enhances security for US public sector organizations. The platform provides numerous networking and security services that improve user experience, including Rate Limiting, Load Balancing, Bot Management, CDN, Enterprise grade DNS, Zero Trust Network Access, Remote Browser Isolation, Secure Web Gateway, L3/4 DDoS, Network Interconnect, Workers, Workers KV, and Durable Objects. Cloudflare for Government is currently available in the US but will be expanded to allow governments worldwide to use its services.
Dec 14, 2022
858 words in the original blog post.
Cloudflare has announced its plans to offset historical carbon emissions generated by its global network infrastructure between 2010 and 2017. The company is working towards reducing its greenhouse gas (GHG) emissions to net zero in alignment with the Paris Agreement, which sets out a framework for nations to combat climate change.
To achieve this goal, Cloudflare has invested in purchasing carbon offsets, specifically focusing on renewable energy credits (RECs), and nature-based removals. The company estimates that its network generated approximately 31,284 metric tons of CO2 equivalent emissions during the period from 2010 to 2017.
Carbon offsetting involves investing in projects or initiatives that reduce, avoid, or remove an amount of greenhouse gas emissions equivalent to those produced by a company's operations. This helps companies compensate for their emissions and achieve net zero status.
The nature-based removals chosen by Cloudflare involve supporting projects that sequester carbon from the atmosphere through activities such as reforestation, regenerative agriculture, and conservation of ecosystems like forests and wetlands. These initiatives not only help mitigate climate change but also contribute to other sustainable development goals, including improved water quality, biodiversity, and economic opportunities for local communities.
By investing in these removals projects, Cloudflare aims to offset its historical emissions and support global efforts towards a more sustainable future. The company plans to continue working on reducing its current and future GHG emissions through energy efficiency improvements, renewable energy procurement, and other innovative solutions.
This announcement highlights the growing importance of corporate responsibility in addressing climate change and underscores Cloudflare's commitment to sustainability. As more organizations recognize the need for action on this critical issue, we can expect increased investment in carbon offsetting and removals projects as part of their overall strategies for achieving net zero emissions goals.
Dec 14, 2022
1,610 words in the original blog post.
Cloudflare is focusing on sustainability in their office designs and operations, with goals to use sustainable construction materials, efficient operations, and renewable energy purchasing. They have implemented rainwater harvesting systems, bee colonies for honey production, and cultural changes among staff to reduce waste streams. Additionally, they are reusing existing furniture as much as possible to keep it out of landfills.
Dec 14, 2022
1,454 words in the original blog post.
Starting December 13, 2022, Cloudflare will provide enterprise-level Zero Trust cybersecurity solutions to under-resourced critical infrastructure organizations at no cost and with no time limit. This initiative, called Project Safekeeping, aims to support vulnerable entities that face constant cyber attacks threatening health, safety, and security in our global communities. Smaller critical infrastructure organizations are often at risk due to budget constraints and lack of capacity to manage relentless cyber threats. Cloudflare's Zero Trust services include connecting users to applications, filtering traffic, securing cloud applications, protecting sensitive data, email security, and safer web browsing. Eligible entities should be located in Australia, Japan, Germany, Portugal, and the United Kingdom; considered critical infrastructure by governments; and have approximately up to 50 people and/or less than USD $10 million in annual revenue or balance sheet total. Interested organizations can apply via Cloudflare's website.
Dec 13, 2022
886 words in the original blog post.
Small businesses are often targeted by cyber attacks, with 43% of such incidents aimed at them according to research. With limited resources to manage IT systems and security protections, these companies may struggle to predict, stop or mitigate any cyber threats that could affect their bottom lines. Cloudflare's mission is to help build a better internet by providing all businesses with access to the best security and performance services available. The company identified over 94,000 small customers using at least one of its services in 2022, helping mitigate over 38,000 Layer 3 DDoS attacks for these businesses. As of December 2022, there were also 4.2 million Cloudflare accounts using only services available in the company's Free plan, representing a significant increase year-over-year.
Dec 13, 2022
1,194 words in the original blog post.
The United States Department of Commerce has announced that all 50 states and eligible territories have signed on to the "Internet for All" initiative, which aims to close the Digital Divide through new broadband deployment and digital equity programs. Funded by $65 billion in Congress's Infrastructure Investment and Jobs Act (IIJA), the initiative includes various measures such as funding for broadband deployment, subsidy for low-income families, digital equity improvement, connectivity on tribal lands, and "middle-mile" capacity establishment. While significant work remains to ensure all Americans have access to affordable high-speed internet, this government investment in broadband infrastructure is a positive step towards building a better Internet experience.
Dec 13, 2022
959 words in the original blog post.
Cloudflare's Project Pangea, launched in July 2021, aims to provide free access to the Internet for underserved community networks. Initially, participants were required to bring at least a /24 block of IP space; however, this requirement has now been relaxed to support more communities. Through Project Pangea, eligible networks can access various services such as internet connectivity, DDoS protection, network firewalling, and traffic acceleration for free. By partnering with community networks worldwide, Cloudflare helps provide secure, fast, and reliable Internet access through its global network while mitigating malicious traffic and empowering operators to focus on managing the last mile connections. One example is Ayva Networks in Colorado, which has experienced improved connectivity and firewall performance after connecting through Magic Transit. Project Pangea's benefits include simplifying network integration and now supporting customers without their own IP address space. Interested community networks can apply for Project Pangea on its landing page.
Dec 13, 2022
833 words in the original blog post.
The Montgomery, Alabama Internet Exchange (MGMix) is a key infrastructure for improving internet connectivity in the region. With local leaders' support, MGMix launched in 2016 and later upgraded to 100 Gbps of capacity. The exchange enables local networks to freely exchange traffic, reducing the cost of delivering internet traffic and making the internet faster through better interconnection. MGMix has attracted a diverse range of members, including ISPs, institutions, content providers, and services like Cloudflare. As MGMix expands to Auburn, it promises further benefits for underserved rural communities. Internet Exchanges play an essential role in enhancing the internet's performance and efficiency worldwide, which is why organizations like Cloudflare join and support them.
Dec 13, 2022
1,175 words in the original blog post.
Project Galileo was launched in 2014 with a mission to protect free expression from cyber attacks. Over the past eight years, Cloudflare has collaborated with over 50 civil society partners to provide powerful cyber security tools to more than 2,000 organizations across 111 countries. These organizations work in sensitive areas of human rights and democracy building. In response to new threats stemming from global events like COVID-19 and the war in Ukraine, Cloudflare has extended its Zero Trust products to all domains under Project Galileo, making enterprise-level cyber security accessible to organizations regardless of their size or budgets. Additionally, Cloudflare has partnered with the CyberPeace Institute, Information Technology Disaster Resource Center (ITDRC), and Meedan for this initiative. For those interested in protection through Project Galileo, they can visit Cloudflare's website for more information.
Dec 12, 2022
1,171 words in the original blog post.
Cloudflare has expanded its offering under the Athenian Project to include its Area 1 email security suite for state and local governments, aiming to protect against phishing attacks and keep voter data safe. The company's mission is to help build a better internet by promoting democracy and ensuring access to information. Under the Athenian Project, Cloudflare provides its highest level of services for free to state and local governments running elections. It has been able to provide these services to election entities in 31 states across the US. The company's work in protecting elections includes providing DDoS protection, Web Application Firewall, SSL encryption, and other security features that focus on web applications.
Dec 12, 2022
1,223 words in the original blog post.
Cloudflare has protected over 100 political campaigns and election officials in the United States, successfully processing over 20 million emails and preventing around 150K phishing attacks from reaching campaign inboxes during the recent midterm elections. The company's Area 1 solution uses preemptive campaign discovery and machine learning algorithms to analyze various threat signals, such as email attachments, sender domains, and sentiment within the email itself. This helps to determine if an email is malicious or not, ensuring secure communication for political campaigns and democratic institutions.
Dec 12, 2022
1,028 words in the original blog post.
Cloudflare has announced that it will be making its Cloudflare One Zero Trust suite available for free to organizations qualified for Projects Galileo and Athenian. The initiative is aimed at protecting smaller teams, such as those focused on journalism, artistic expression, human rights, and state and local governments working towards democracy in the United States.
The Cloudflare One Zero Trust suite includes three key features: protection against phishing attacks, secure connections for employees and partners, and encryption of users' path to the Internet. The service can be configured and deployed within hours, offering comprehensive security without requiring a large IT department. Interested organizations can apply here and here.
This move demonstrates Cloudflare's commitment to supporting smaller teams and organizations in protecting their data and operations from potential cyber threats.
Dec 12, 2022
1,454 words in the original blog post.
The US government has recently issued a new General License that broadens the products/services authorized by internet infrastructure companies in Iran, making it easier for these companies to provide services to ordinary Iranians without violating sanctions. While this move is encouraging, there are still significant restrictions in place and logistical challenges to overcome when dealing with high-risk countries such as Iran. The UK and EU have not issued any internet-related General Licenses, which has become an issue in Russia due to recent restrictions on the internet.
Dec 12, 2022
1,909 words in the original blog post.
Since Russia invaded Ukraine on February 24, 2022, Ukrainian infrastructure has been targeted by cyberattacks including DDoS attacks and other common threats. Cybersecurity company Cloudflare has provided free services and support to the Ukrainian government, critical infrastructure providers, and nonprofit organizations in the region to combat these attacks. As Russian troops advanced into Ukraine, physical security of internet infrastructure also became a significant concern. This prompted companies to adopt new models of security including moving data to public clouds for better protection. Internet disruptions due to power outages and deliberate manipulation have emerged as tools in armed conflict, disrupting communication channels and accessibility to information. Cloudflare continues to provide tools to protect critical services from cyberattacks and improve security for entities operating in the region. The company is committed to sharing information about the internet situation within Ukraine.
Dec 12, 2022
1,098 words in the original blog post.
Protests began in Iran on September 16 following the death of Mahsa Amini, leading to civil unrest and an impact on internet usage within the country. The Iranian government introduced internet restrictions, including bans on Instagram and WhatsApp, but despite these efforts, internet use has surged since the beginning of the protests. This highlights the critical role the internet now plays in people's lives, even under authoritarian regimes. Since 2013, Iran has been working towards creating a National Infrastructure Network (NIN), aiming to recreate essential internet services within the country and control and monitor them domestically. However, despite this effort, internet access remains crucial for economic activity and everyday life in Iran.
Dec 12, 2022
984 words in the original blog post.
Matthew Prince, co-founder and CEO of Cloudflare, shares the importance of mission in attracting talent to his company. He discusses how their mission to help build a better internet developed over time and now includes a focus on privacy, security, interoperability, and wide availability. The author highlights various challenges facing the internet today but also emphasizes its potential to bring together marginalized people from around the world and improve lives in developing countries. Throughout Impact Week, Cloudflare plans to share stories about how they are working to make the internet more accessible and secure for all, while also addressing sustainability issues.
Dec 11, 2022
1,334 words in the original blog post.
Cloudflare has introduced a WAF attack scoring system in general availability to enhance its existing Web Application Firewall (WAF) services. This new feature allows gradual access for customers on Enterprise Core and Advanced Security bundles, with other Enterprise clients gaining access over the coming months. The WAF attack scoring system is designed to classify all requests using a model trained on data from millions of Internet properties protected by Cloudflare's network. It complements the company's existing security features, such as Bot Management and Content Scanning, allowing users to filter potentially malicious attacks before deploying any rules. The attack scores are also available in HTTP logs and can be used when building custom rules or rate-limiting rules for enhanced protection against various web application threats.
Dec 09, 2022
1,385 words in the original blog post.
Cloudflare has launched a new Security Analytics tool designed to provide users with a security lens across all of their HTTP traffic. This approach, known as "detect then mitigate," allows users to explore the entirety of their traffic to understand what is happening and where. The tool includes top statistics, in-context quick filters, and supports rapid exploration and validation. It combines existing components like attack analysis, bot analysis, and other security signals from Cloudflare products. Currently available for Enterprise customers, it aims to improve visibility and intelligence for better protection of web applications, and feedback is encouraged to enhance the user experience.
Dec 09, 2022
1,241 words in the original blog post.
Alex Kim has joined Cloudflare as Country Manager of South Korea to expand its customer base in Korea. He is the first official employee of Cloudflare Korea LLC in Seoul and aims to establish the company as a trusted cloud security provider in the country. Kim believes that as the pace of cloud transformation accelerates, companies need to focus on security, and few firms can deploy it more easily than Cloudflare. With recent government moves to ease regulations, Kim expects the pace of cloud transformation to increase in Korea. He plans to promote the value of Cloudflare in the Korean market and contribute to expanding its business and creating jobs in the country.
Dec 08, 2022
945 words in the original blog post.