Account Access Management & Permissions
Inside Cloudflare: Preventing Account Takeovers

Inside Cloudflare: Preventing Account Takeovers

3/30/2021 · Julie A. Sparks

What this post added

This post details how Cloudflare's Security Team uses Cloudflare products (Gateway, Access) and internal engineering to prevent account takeovers on its own applications. It highlights the use of FIDO2 hardware security tokens, managed corporate device policies in Access, and custom detections built on Gateway/Access logs to protect against various account takeover techniques like credential stuffing, phishing, and SIM-swapping. It also discusses the importance of influencing the product roadmap based on internal security needs.

Read the original post ↗