The Web is World-Wide, or who still needs RC4?2014-05-19TLSRC4SecurityCryptographyTwo weeks ago we changed our TLS configuration to deprioritize the RC4 encryption method because it is widely thought to be vulnerable to attack. At the time we had an internal debate about turning off RC4 altogether, but statistics showed that we couldn't....John Graham-Cumming
Killing RC4: The Long Goodbye2014-05-07TLSRC4AttacksHTTPSProduct NewsSecurityAt CloudFlare we spend a lot of time thinking about the best way to keep our customers’ data safe. Despite recent troubles, HTTPS is still the best way to deliver encrypted content for the web. ...Nick Sullivan
Tracking our SSL configuration2014-05-03OpenSSLSSLOver time we've updated the SSL configuration we use for serving HTTPS as the security landscape has changed. In the past we've documented those changes in blog posts....John Graham-Cumming
Searching for The Prime Suspect: How Heartbleed Leaked Private Keys2014-04-27TLSHTTPSOpenSSLVulnerabilitiesSecurityWithin a few hours of CloudFlare launching its Heartbleed Challenge the truth was out. Not only did Heartbleed leak private session information (such as cookies and other data that SSL should have been protecting), but the crown jewels of an HTTPS web server were also vulnerable....John Graham-Cumming
Upcoming Meetups at CloudFlare2014-04-21MeetUpCloudflare MeetupsEventsCryptographyAt CloudFlare, we love connecting with our communities, and so we are excited to announce two meetups to be hosted here at the CloudFlare headquarters in San Francisco next month....Kristin Tarr
The Hidden Costs of Heartbleed2014-04-17OCSPHTTPSVulnerabilitiesReliabilitySSLOpenSSLSecurityA quick followup to our last blog post on our decision to reissue and revoke all of CloudFlare's customers' SSL certificates. One question we've received is why we didn't just reissue and revoke all SSL certificates as soon as we got word about the Heartbleed vulnerability?...Matthew Prince
The Heartbleed Aftermath: all CloudFlare certificates revoked and reissued2014-04-17TLSHTTPSOpenSSLVulnerabilitiesSecurityCryptographyEleven days ago the Heartbleed vulnerability was publicly announced. Last Friday, we issued the CloudFlare Challenge: Heartbleed and simultaneously started the process of revoking and reissuing all the SSL certificates....Nick Sullivan
Certificate Revocation and Heartbleed2014-04-12HTTPSReliabilitySSLCommunityVulnerabilitiesSecurityAs you may have noticed, the CloudFlare Heartbleed Challenge has been solved. The private key for the site cloudflarechallenge.com has been obtained by several authorized attackers via the Heartbleed exploit....Nick Sullivan
The Results of the CloudFlare Challenge2014-04-11VulnerabilitiesReliabilityCommunityEarlier today we announced the Heartbleed Challenge. We set up a nginx server with a vulnerable version of OpenSSL and challenged the community to steal its private key....Nick Sullivan
Answering the Critical Question: Can You Get Private SSL Keys Using Heartbleed?2014-04-11VulnerabilitiesBugsSSLOpenSSLReliabilityBelow is what we thought as of 12:27pm UTC. To verify our belief we crowd sourced the investigation. It turns out we were wrong. While it takes effort, it is possible to extract private SSL keys....Nick Sullivan
Jetpack for WordPress: automatic protection2014-04-10WordPressSpeed & ReliabilityVulnerabilitiesAs we've said before, lots of our users run WordPress on their websites and its popularity makes it a big target. So when a new vulnerability is discovered, acting quickly is prudent....Simon Moore
Staying ahead of OpenSSL vulnerabilities2014-04-07TLSBugsOpenSSLVulnerabilitiesReliabilitySecuritySSLToday a new vulnerability was announced in OpenSSL 1.0.1 that allows an attacker to reveal up to 64kB of memory to a connected client or server (CVE-2014-0160). We fixed this vulnerability last week before it was made public. ...Nick Sullivan
Introducing CNAME Flattening: RFC-Compliant CNAMEs at a Domain's Root2014-04-03ReliabilityDNSThis post is about a new feature we've been quietly rolling out over the last few months. Last week we began enabling it for everyone by default. ...Matthew Prince
The weird and wonderful world of DNS LOC records2014-04-01RRDNSDNSReliabilityAttacksGoA cornerstone of CloudFlare's infrastructure is our ability to serve DNS requests quickly and handle DNS attacks. To do both those things we wrote our own authoritative DNS server called RRDNS in Go. ...John Graham-Cumming
How to ensure your server's software stays secure?2014-03-17DDoSRSAEventsAt CloudFlare, security is on the top of our minds. We are always looking for ways to better secure the data we are entrusted with and improve the security of our customers' websites. ...Elenitsa Staykova
I joined CloudFlare on Monday along with 5,000 others2014-03-13IPv6Cloudflare HistoryLife at CloudflareThere are days when you feel quite ecstatic and know you have succeeded in completing each and every task set before you. Monday was one of those days - well nearly....Martin J Levy
What do you do when the world’s attention is on you?2014-03-12CustomersSpeed & ReliabilitySXSWThis is a guest post from Rodney Gibbs. Rodney is the CIO of The Texas Tribune, a nonprofit media organization that covers public policy, politics, and government. ...Guest Author
The Web's Silver Jubilee2014-03-11HistoryspdyTLSSSLSecurityNo matter what your age, it's hard to believe that the World-Wide Web is 25 today. For the young the web has always been part of their lives, for the older it seems like it was invented only yesterday....John Graham-Cumming
WordPress Pingback Attacks and our WAF2014-03-11WordPressWAFAttacksAt CloudFlare a lot of our customers use WordPress, that's why we have our own plugin, we hang out at WordCamp and we wrote a WordPress specific ruleset for our Web Application Firewall....Simon Moore
ECDSA: The digital signature algorithm of a better internet2014-03-10TLSHTTPSElliptic CurvesRSASecurityCryptographyThis blog post is dedicated to the memory of Dr. Scott Vanstone, popularizer of elliptic curve cryptography and inventor of the ECDSA algorithm. He passed away on March 2, 2014....Nick Sullivan