
10/8/2019 · John Graham-Cumming
What this post added
This post details Cloudflare's internal security culture, including a blame-free incident reporting system, the use of HackerOne for external reporting, and a private bug bounty program. It also highlights the critical role of identity and authentication, with Cloudflare building its own solutions like Cloudflare Access, and enforcing strong password policies and multi-factor authentication (Yubikeys, TOTP, no SMS). The post emphasizes the importance of transparency in security, citing the Cloudbleed incident and subsequent detailed blog posts as examples of how openness builds trust. It also discusses the shift towards memory-safe languages like Go and Rust for software development to prevent future vulnerabilities, and the top-down commitment to security, with the CSO reporting to the CEO.