
3/30/2021 · Julie A. Sparks
What this post added
This post details how Cloudflare's Security Team uses Cloudflare products (Gateway, Access) and internal engineering to prevent account takeovers on its own applications. It highlights the use of FIDO2 hardware security tokens, managed corporate device policies in Access, and custom detections built on Gateway/Access logs to protect against various account takeover techniques like credential stuffing, phishing, and SIM-swapping. It also discusses the importance of influencing the product roadmap based on internal security needs.