Website Security & Threat Management
Talk Transcript: How Cloudflare Thinks About Security

Talk Transcript: How Cloudflare Thinks About Security

10/8/2019 · John Graham-Cumming

What this post added

This post details Cloudflare's internal security culture, including a blame-free incident reporting system, the use of HackerOne for external reporting, and a private bug bounty program. It also highlights the critical role of identity and authentication, with Cloudflare building its own solutions like Cloudflare Access, and enforcing strong password policies and multi-factor authentication (Yubikeys, TOTP, no SMS). The post emphasizes the importance of transparency in security, citing the Cloudbleed incident and subsequent detailed blog posts as examples of how openness builds trust. It also discusses the shift towards memory-safe languages like Go and Rust for software development to prevent future vulnerabilities, and the top-down commitment to security, with the CSO reporting to the CEO.

Read the original post ↗