Home / Companies / Cloudflare / Blog / Post Details
Content Deep Dive

Staying afloat: the DROWN Attack and CloudFlare

Blog post from Cloudflare

Post Details
Company
Date Published
Author
John Graham-Cumming
Word Count
99
Company Posts That Month
7
Language
English
Hacker News Points
-
Post removed?
No
Summary

On March 1st, 2016, John Graham-Cumming announced that CloudFlare customers are automatically protected against the DROWN Attack due to their lack of SSLv2 enabled on servers. The company's SSL configuration is published for others to use and currently accepts TLS 1.0, 1.1, and 1.2. They are proactively testing customers' origin web servers for vulnerabilities and will reach out to those with vulnerable servers. In the meantime, users should ensure that SSLv2 is fully disabled or private keys are not shared with servers still needing SSLv2.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.