Website Security & Threat Management
How Cloudflare implemented hardware keys with FIDO2 and Zero Trust to prevent phishing

How Cloudflare implemented hardware keys with FIDO2 and Zero Trust to prevent phishing

9/29/2022 · Evan Johnson, Derek Pitts

What this post added

This post details Cloudflare's internal migration from VPN-based authentication with TOTP to a Zero Trust architecture enforced by Cloudflare Access and FIDO2/WebAuthn security keys. It describes the selective enforcement strategy using OAuth2 AMR values and Terraform, the eventual full enforcement of FIDO2, and the extension of this security model to SSH connections via Cloudflare Tunnel and cloudflared.

Read the original post ↗