
3/30/2021 · Michael Tremante
What this post added
This post introduces several new features aimed at enhancing end-user account security and preventing account takeovers. These include: a managed list of open proxy IPs for firewall rules, Super Bot Fight Mode for Pro and Business plans to combat credential stuffing, Exposed Credential Checks within the WAF to identify and flag logins using compromised credentials (using a privacy-preserving cryptographic protocol), Cloudflare Access integration with managed device serial numbers for stricter access control, and rate limiting on failed login attempts to slow down brute-force attacks.