Cloudflare
   HOME

TheInfoList



OR:

Cloudflare, Inc. is an American
content delivery network A content delivery network, or content distribution network (CDN), is a geographically distributed network of proxy servers and their data centers. The goal is to provide high availability and performance by distributing the service spatially rel ...
and DDoS mitigation company, founded in 2009. It primarily acts as a
reverse proxy In computer networks, a reverse proxy is the application that sits in front of back-end applications and forwards client (e.g. browser) requests to those applications. Reverse proxies help increase scalability, performance, resilience and securi ...
between a website's visitor and the Cloudflare customer's hosting provider. Its headquarters are in San Francisco, California. According to '' The Hill'', it is used by more than 20 percent of the entire Internet for its web security services.


History

Cloudflare was founded in July 2009 by Matthew Prince, Lee Holloway, and
Michelle Zatlyn Michelle Zatlyn is co-founder, president, and chief operating officer of the cybersecurity firm Cloudflare. She also serves on the company's board of directors. Early life and education Zatlyn was raised in Prince Albert, Saskatchewan, Canada. ...
. Prince and Holloway had previously collaborated on
Project Honey Pot Project Honey Pot is a web-based honeypot network operated by Unspam Technologies, Inc. It uses software embedded in web sites. It collects information about the IP addresses used when harvesting e-mail addresses in spam, bulk mailing, and o ...
, a product of Unspam Technologies that served as some inspiration for the basis of Cloudflare. From 2009, the company was venture-capital funded. On August 15, 2019, Cloudflare submitted its S-1 filing for IPO on the
New York Stock Exchange The New York Stock Exchange (NYSE, nicknamed "The Big Board") is an American stock exchange in the Financial District of Lower Manhattan in New York City. It is by far the world's largest stock exchange by market capitalization of its listed ...
under the stock ticker NET. It opened for public trading on September 13, 2019 at $15 per share. In 2020, Cloudflare co-founder and COO Michelle Zatlyn was named president, making her one of the few woman presidents of a publicly traded technology company in the U.S. Cloudflare has acquired web-services and security companies, including StopTheHacker (Feb 2014), CryptoSeal (June 2014), Eager Platform Co. (December 2016), Neumob (November 2017), S2 Systems (January 2020), Linc (December 2020), Zaraz (December 2021), Vectrix (February 2022), and
Area 1 Security Area 1 Security, Inc. was an American cybersecurity company based in Redwood City, California which merged into Cloudflare in February 2022. History Area 1 was incorporated in 2013 by Oren Falkowitz, Blake Darché, and Phil Syme, previously empl ...
(February 2022). Since at least 2017, Cloudflare has been using a wall of
lava lamp A lava lamp is a decorative lamp, invented in 1963 by British entrepreneur Edward Craven Walker, the founder of the lighting company Mathmos. It consists of a bolus of a special coloured wax mixture inside a glass vessel, the remainder of which ...
s in their San Francisco headquarters as a source of randomness for encryption keys, alongside double pendulums in its London offices and a geiger counter in its Singapore offices. The lava lamp installation implements the Lavarand method, where a camera transforms the unpredictable shapes of the "lava" blobs into a digital image.


Claims regarding DDoS mitigation

Cloudflare received media attention in June 2011 for providing DDoS mitigation for the website of
LulzSec LulzSec (a contraction for Lulz Security) was a black hat computer hacking group that claimed responsibility for several high profile attacks, including the compromise of user accounts from PlayStation Network in 2011. The group also claimed ...
, a
black hat hacking A Black Hat (Black Hat Hacker or Blackhat) is a computer hacker who usually violates laws or typical ethical standards. The term originates from the 1950s westerns, when bad guys typically wore black hats and good guys white hats. Black hat hacker ...
group. In March 2013,
The Spamhaus Project The Spamhaus Project is an international organisation based in the Principality of Andorra, founded in 1998 by Steve Linford to track email spammers and spam-related activity. The name ''spamhaus'', a pseudo-German expression, was coined by Linf ...
was targeted by a DDoS attack that Cloudflare reported exceeded 300 gigabits per second (Gbit/s). Patrick Gilmore, of Akamai, stated that at the time it was "the largest publicly announced DDoS attack in the history of the Internet." While trying to defend Spamhaus against the DDoS attacks, Cloudflare ended up being attacked as well; Google and other companies eventually came to Spamhaus' defense and helped it to absorb the unprecedented amount of attack traffic. In February 2014, Cloudflare claimed to have mitigated an NTP reflection attack against an unnamed European customer, which they stated peaked at 400 Gbit/s. In November 2014, it reported a 500 Gbit/s DDoS attack in Hong Kong. In June 2020, it mitigated a DDoS attack that peaked at 250 Gbit/s. In July 2021 the company claimed to have absorbed a DDoS attack three times larger than any they'd previously recorded, which their corporate blog implied was over 1.2 
Tbit/s In telecommunications, data-transfer rate is the average number of bits ( bitrate), characters or symbols ( baudrate), or data blocks per unit time passing through a communication link in a data-transmission system. Common data rate units are mu ...
in total.


Products

Cloudflare acts as a
reverse proxy In computer networks, a reverse proxy is the application that sits in front of back-end applications and forwards client (e.g. browser) requests to those applications. Reverse proxies help increase scalability, performance, resilience and securi ...
for
web traffic Web traffic is the data sent and received by visitors to a website. Since the mid-1990s, web traffic has been the largest portion of Internet traffic. Sites monitor the incoming and outgoing traffic to see which parts or pages of their site are ...
. It supports web protocols including
SPDY SPDY (pronounced "speedy") is an obsolete open-specification communication protocol developed for transporting web content. SPDY became the basis for HTTP/2 specification. However, HTTP/2 diverged from SPDY and eventually HTTP/2 subsumed all u ...
and
HTTP/2 HTTP/2 (originally named HTTP/2.0) is a major revision of the HTTP network protocol used by the World Wide Web. It was derived from the earlier experimental SPDY protocol, originally developed by Google. HTTP/2 was developed by the HTTP Working ...
,
QUIC QUIC (pronounced "quick") is a general-purpose transport layer network protocol initially designed by Jim Roskind at Google, implemented, and deployed in 2012, announced publicly in 2013 as experimentation broadened, and described at an IETF meet ...
, and support for HTTP/2 Server Push. Cloudflare provides DDoS mitigation services that protect customers from distributed
denial of service In computing, a denial-of-service attack (DoS attack) is a cyber-attack in which the perpetrator seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host connec ...
(DDoS) attacks. In 2010, Cloudflare launched a
Content Distribution Network A content delivery network, or content distribution network (CDN), is a geographically distributed network of proxy servers and their data centers. The goal is to provide high availability and performance by distributing the service spatially rel ...
(CDN) service.
TechCrunch TechCrunch is an American online newspaper focusing on high tech and startup companies. It was founded in June 2005 by Archimedes Ventures, led by partners Michael Arrington and Keith Teare. In 2010, AOL acquired the company for approximately $ ...
wrote that its goal was to be "a CDN for the masses". In 2017 Cloudflare launched Cloudflare Workers, a
serverless computing Serverless computing is a cloud computing execution model in which the cloud provider allocates machine resources on demand, taking care of the servers on behalf of their customers. "Serverless" is a misnomer in the sense that servers are still ...
platform for creating new applications, augmenting existing ones, without configuring or maintaining infrastructure. It has expanded to include Workers KV, a low-latency key-value data store; Cron Triggers, for scheduling Cron jobs; and additional tooling for developers to deploy and scale their code across the globe. On September 25, 2019, Cloudflare released a freemium
VPN service A virtual private network (VPN) service provides a proxy server to help users bypass Internet censorship such as geoblocking and users who want to protect their communications against data profiling or MitM attacks on hostile networks. A wide va ...
for mobile devices called WARP. A year later, beta support for macOS and Windows was released. As of 2020, Cloudflare was providing DNS services to over 100,000 customers. In November, 2020, Cloudflare announced Cloudflare for Teams, consisting of a DNS resolver and web gateway called "Gateway," and a zero-trust authentication service called "Access." On May 11, 2022, Cloudflare announced its first SQL database, D1, which is built on
SQLite SQLite (, ) is a database engine written in the C programming language. It is not a standalone app; rather, it is a library that software developers embed in their apps. As such, it belongs to the family of embedded databases. It is the m ...
. On September 26, 2022, Cloudflare announced Zero Trust SIM, an eSIM designed to secure mobile devices and prevent SIM-swapping attacks. The technology is based on the
zero trust security model The zero trust security model, also known as zero trust architecture (ZTA), zero trust network architecture or zero trust network access (ZTNA), and sometimes known as perimeterless security, describes an approach to the design and implementation ...
. According to Cloudflare, the secure eSIM can also be used as a second identification factor with
2FA Multi-factor authentication (MFA; encompassing two-factor authentication, or 2FA, along with similar terms) is an electronic authentication method in which a user is granted access to a website or application only after successfully presenting ...
verification protocols. The product will be first available in the United States, with a planned global rollout in the future. In September 2022, Cloudflare began to test Turnstile – an alternative to
CAPTCHA A CAPTCHA ( , a contrived acronym for "Completely Automated Public Turing test to tell Computers and Humans Apart") is a type of challenge–response test used in computing to determine whether the user is human. The term was coined in 2003 b ...
. The product, instead of presenting a visual CAPTCHA for the user to solve, automatizes the verification process by conducting JavaScript-based checks inside the browser to determine whether the user is a real person or an automated entity. The algorithm reportedly uses machine learning to optimize the process.


Free services

In 2014, Cloudflare began providing free DDoS mitigation for artists, activists, journalists, and human rights groups under the name "Project Galileo." More than 1,000 users and organizations were participating in Project Galileo as of 2020. In 2017, they extended the service to electoral infrastructure and political campaigns under the name "Athenian Project." In December 2020, Cloudflare released a beta Jamstack platform for front-end developers to deploy websites on Cloudflare's infrastructure, under the name "Pages." In January 2021, the company began providing their "Waiting Room" digital queue product for free for COVID-19 vaccination scheduling under the title "Project Fair Shot." Project Fair Shot later won a Webby People's Choice Award in 2022 for Event Management under the Apps & Software category.


Security and privacy issues


Intrusions

On June 1, 2012, the hacker group
UGNazi UGNazi (Underground Nazi Hacktivist Group) is a hacker group. The group conducted a series of cyberattacks, including social engineering, data breach, and denial-of-service attacks, on the websites of various organizations in 2012. Two members of ...
redirected visitors to the website
4chan 4chan is an anonymous English-language imageboard website. Launched by Christopher "moot" Poole in October 2003, the site hosts boards dedicated to a wide variety of topics, from anime and manga to video games, cooking, weapons, television, ...
to a Twitter account belonging to UGNazi by “hijacking” 4chan’s domain via Cloudflare. After initiating a password recovery for the
Google Workspace Google Workspace (formerly known as Google Apps and later G Suite) is a collection of cloud computing, productivity and collaboration tools, software and products developed and marketed by Google. It consists of Gmail, Contacts, Calendar, Meet ...
hosted email account of Cloudflare CEO Matthew Prince, UGNazi then allegedly used social engineering to trick AT&T support staff into giving them access to his voicemail. Exploiting a bug in Google App’s two-factor authentication security procedures, the hackers allegedly used the voicemail-recovered password to access Prince’s email account without a second layer of authentication. Once in control of Prince’s email account, they were able to redirect the 4chan domain through Cloudflare’s database. In March 2021, Tillie Kottmann from the hacking collective "Advanced Persistent Threat 69420" demonstrated that the group had gained root shell access to security cameras in Cloudflare offices managed by cloud-based physical security company
Verkada Verkada Inc. is a San Mateo, CA-based company that develops cloud-based building security systems. The company combines security equipment such as video cameras, access control systems and environmental sensors, with cloud based machine vision and ...
after obtaining the credentials of a Verkada superuser account that had been leaked on the Internet. Cloudflare stated that the compromised cameras were in offices that had been officially closed for several months, though the hacking collective also obtained access to Verkada-operated cameras in Cloudflare's offices in New York City, London, Austin and San Francisco. The hacking group told ''
Bloomberg News Bloomberg News (originally Bloomberg Business News) is an international news agency headquartered in New York City and a division of Bloomberg L.P. Content produced by Bloomberg News is disseminated through Bloomberg Terminals, Bloomberg Tele ...
'' that it had video archives from all Verkada customers; it accessed footage from Cloudflare's cameras and posted a screenshot of security footage which they said was taken by a Verkada camera in a Cloudflare office.


Data leaks

From September 2016 until February 2017, a major Cloudflare bug (nicknamed Cloudbleed) leaked sensitive data, including passwords and authentication tokens, from customer websites by sending extra data in response to web requests. The leaks resulted from a
buffer overflow In information security and programming, a buffer overflow, or buffer overrun, is an anomaly whereby a program, while writing data to a buffer, overruns the buffer's boundary and overwrites adjacent memory locations. Buffers are areas of memo ...
which occurred, according to numbers provided by Cloudflare at the time, more than 18,000,000 times before the problem was corrected. In May 2017, ''
ProPublica ProPublica (), legally Pro Publica, Inc., is a nonprofit organization based in New York City. In 2010, it became the first online news source to win a Pulitzer Prize, for a piece written by one of its journalists''The Guardian'', April 13, 2010P ...
'' reported that Cloudflare routinely discloses the names and email addresses of persons complaining about hate sites to the operators of those sites, which has led to the complainants being harassed. Cloudflare's
general counsel A general counsel, also known as chief counsel or chief legal officer (CLO), is the chief in-house lawyer for a company or a governmental department. In a company, the person holding the position typically reports directly to the CEO, and their ...
defended the company's policies by saying it is "base constitutional law that people can face their accusers", and noted that there had been a disclaimer on Cloudflare's complaint form since 2015 stating that they "would notify the site owner." Cloudflare's CEO later suggested that, had people not wanted their names shared, they should have provided a false name on the reporting form.


Service outages

There was major outage lasting about 30 minutes, on July 2, 2019 attributed to bad
software deployment Software deployment is all of the activities that make a software system available for use. The general deployment process consists of several interrelated activities with possible transitions between them. These activities can occur on the ...
. In 2020, a misconfiguration of a router caused a data pileup and outage in major European cities. Cloudflare experienced another outage in June 2022.


Controversies

Cloudflare has been criticized for not banning websites with hate speech content. The company has said it has a content neutrality policy and that it opposes the policing of its customers on
free speech Freedom of speech is a principle that supports the freedom of an individual or a community to articulate their opinions and ideas without fear of retaliation, censorship, or legal sanction. The right to freedom of expression has been recog ...
grounds, except in cases where the customers break the law. The company has also faced criticism for not banning websites allegedly connected to terrorism groups, but Cloudflare has maintained that no law enforcement agency has asked the company to discontinue these services and it closely monitors its obligations under U.S. laws. In 2022, a report by Stanford University found that Cloudflare was a prominent CDN provider among several other providers that are disproportionately responsible for serving misinformation websites.


Far-right content

Cloudflare has come under pressure on multiple occasions due to its services being utilized to serve hate speech and far-right content. As Cloudflare is considered an infrastructure provider, rather than a hosting provider, they are able to maintain broad legal immunity for the content served from their customers.


''The Daily Stormer''

Cloudflare provided DNS routing and DDoS protection for the
white supremacist White supremacy or white supremacism is the belief that white people are superior to those of other races and thus should dominate them. The belief favors the maintenance and defense of any power and privilege held by white people. White s ...
and neo-Nazi website, ''
The Daily Stormer ''The Daily Stormer'' is an American far-right, neo-Nazi, white supremacist, misogynist, Islamophobic, antisemitic, and Holocaust denial commentary and message board website that advocates for a second genocide of Jews. It is part of the al ...
.'' In 2017 Cloudflare stopped providing its services to ''The Daily Stormer'' after an announcement on the website asserted that the "upper echelons" of Cloudflare were "secretly supporters of their ideology". Previously Cloudflare had refused to take any action regarding ''The Daily Stormer''. As a self-described "free speech absolutist", Cloudflare's CEO Matthew Prince, in a blog post, vowed never to succumb to external pressure again and sought to create a "political umbrella" for the future. Prince further addressed the dangers of large companies deciding what is allowed to stay online, a concern that is shared by a number of civil liberties groups and privacy experts. The Electronic Frontier Foundation, a US digital rights group, said that services such as Cloudflare "should not be adjudicating what speech is acceptable", adding that "when illegal activity, like inciting violence or defamation, occurs, the proper channel to deal with it is the legal system."


Mass shootings and 8chan

In 2019, Cloudflare was criticized for providing services to the far-right discussion and imageboard
8chan 8kun, previously called 8chan, Infinitechan or Infinitychan (stylized as ∞chan), is an imageboard website composed of user-created message boards. An owner moderates each board, with minimal interaction from site administration. The site ha ...
, which allows users to post and discuss content with minimal interference from site administrators. The message board has been linked to mass shootings in the United States and the
Christchurch mosque shootings On 15 March 2019, two consecutive mass shootings occurred in a terrorist attack on two mosques in Christchurch, New Zealand. The attacks, carried out by a lone gunman who entered both mosques during Friday prayer, began at the Al Noor Mosque ...
in New Zealand. In addition, a number of news organizations including ''
The Washington Post ''The Washington Post'' (also known as the ''Post'' and, informally, ''WaPo'') is an American daily newspaper published in Washington, D.C. It is the most widely circulated newspaper within the Washington metropolitan area and has a large nati ...
'' and ''
The Daily Dot ''The Daily Dot'' is a digital media company covering the culture of the Internet and the World Wide Web. Founded by Nicholas White in 2011, ''The Daily Dot'' is headquartered in Austin, Texas. The site, conceived as the Internet's "hometo ...
'' have reported on the existence of
child pornography Child pornography (also called CP, child sexual abuse material, CSAM, child porn, or kiddie porn) is pornography that unlawfully exploits children for sexual stimulation. It may be produced with the direct involvement or sexual assault of a ...
and
child sexual abuse Child sexual abuse (CSA), also called child molestation, is a form of child abuse in which an adult or older adolescent uses a child for sexual stimulation. Forms of child sexual abuse include engaging in sexual activities with a child (whet ...
discussion boards. A Cloudflare representative stated that the platform "does not host the referenced websites, cannot block websites, and is not in the business of hiding companies that host illegal content". Cloudflare did not terminate service to
8chan 8kun, previously called 8chan, Infinitechan or Infinitychan (stylized as ∞chan), is an imageboard website composed of user-created message boards. An owner moderates each board, with minimal interaction from site administration. The site ha ...
until public and legal pressure mounted in the wake of the
2019 El Paso shooting On August 3, 2019, a mass shooting occurred at a Walmart store in El Paso, Texas, United States. In the terrorist attack, a far-right individual killed 23 people and injured 23 others. The Federal Bureau of Investigation is investigating the sh ...
, a copycat event similar in nature to the Christchurch mosque shootings, in which the associated manifesto was published to 8chan. In an interview with ''
The Guardian ''The Guardian'' is a British daily newspaper. It was founded in 1821 as ''The Manchester Guardian'', and changed its name in 1959. Along with its sister papers ''The Observer'' and ''The Guardian Weekly'', ''The Guardian'' is part of the Gu ...
'', immediately following the 2019 El Paso shooting, CEO Matthew Prince defended Cloudflare's support of 8chan, stating that he had a "moral obligation" to keep the site online. A few days later Cloudflare terminated their service to 8chan, and as a result the website was taken off the clearnet.


Kiwi Farms

Cloudflare provided DDoS mitigation and acted as a
reverse proxy In computer networks, a reverse proxy is the application that sits in front of back-end applications and forwards client (e.g. browser) requests to those applications. Reverse proxies help increase scalability, performance, resilience and securi ...
for
Kiwi Farms Kiwi Farms, formerly known as CWCki Forums ( ), is an Internet forum that facilitates the discussion and harassment of online figures and communities. Their targets are often subject to organized group trolling and stalking, as well as doxx ...
, a far-right Internet forum dedicated to discussion and
trolling In slang, a troll is a person who posts or makes inflammatory, insincere, digressive, extraneous, or off-topic messages online (such as in social media, a newsgroup, a forum, a chat room, a online video game), or in real life, with the i ...
of online figures or communities, that often engages in harassment and
doxxing Doxing or doxxing is the act of publicly providing personally identifiable information about an individual or organization, usually via the internet. Historically, the term has been used interchangeably to refer to both the aggregation of this in ...
of targets, and has been implicated in the suicides of at least three people. Kiwi Farms also has a reputation for
transphobic Transphobia is a collection of ideas and phenomena that encompass a range of negative attitudes, feelings, or actions towards transgender people or transness in general. Transphobia can include fear, aversion, hatred, violence or anger tow ...
content, and its users have been accused of swatting vulnerable individuals. Although Cloudflare was not the primary website host, they did perform critical services to keep Kiwi Farms on-line, both protecting the site from
denial-of-service attack In computing, a denial-of-service attack (DoS attack) is a cyber-attack in which the perpetrator seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host conn ...
s and optimizing content delivery. Kiwi Farms began as a
4chan 4chan is an anonymous English-language imageboard website. Launched by Christopher "moot" Poole in October 2003, the site hosts boards dedicated to a wide variety of topics, from anime and manga to video games, cooking, weapons, television, ...
forum in 2007, but gained notoriety in 2019, when website owner Joshua Moon reposted a video of the
Christchurch mosque shootings On 15 March 2019, two consecutive mass shootings occurred in a terrorist attack on two mosques in Christchurch, New Zealand. The attacks, carried out by a lone gunman who entered both mosques during Friday prayer, began at the Al Noor Mosque ...
along with the perpetrator's manifesto to the Kiwi Farms site. He refused requests for cooperation from New Zealand law enforcement, when asked to provide information regarding users who may have posted relevant information related to the mosque attacks. In 2022, a campaign was launched by
transgender A transgender (often abbreviated as trans) person is someone whose gender identity or gender expression does not correspond with their sex assigned at birth. Many transgender people experience dysphoria, which they seek to alleviate through ...
activist Clara Sorrenti, who has previously been targeted by the forum, to pressure Cloudflare into terminating service for Kiwi Farms. On August 31, 2022, Cloudflare responded to the campaign with a blog post, and likened their services to that of a public utility, stating that "Just as the telephone company doesn't terminate your line if you say awful, racist, bigoted things, we have concluded ... that turning off security services because we think what you publish is despicable is the wrong policy", but that it would certainly be the "popular choice" to drop sites that the Cloudflare team "personally feels redisgusting and immoral". The company also defended their decision by saying that "where they had provided DDoS protection services to an anti-LGBTIQ+ website, they donated 100% of the fees earned to an organisation fighting for LGBTIQ+ rights". The blog post mentioned Cloudflare's terms of use agreement, which allows them to terminate service due to "content that discloses sensitive personal information, ndincites or exploits violence against people" but, according to ''
The Guardian ''The Guardian'' is a British daily newspaper. It was founded in 1821 as ''The Manchester Guardian'', and changed its name in 1959. Along with its sister papers ''The Observer'' and ''The Guardian Weekly'', ''The Guardian'' is part of the Gu ...
'', the statement "did not specifically address how Kiwi Farms users doxxing people did not fall foul of these terms". Cloudflare has been accused of pinkwashing their message, by highlighting donations for LGBTQ services like
The Trevor Project The Trevor Project is an American nonprofit organization founded in 1998. Focused on suicide prevention efforts among lesbian, gay, bisexual, transgender, queer, and questioning (LGBTQ) youth, they offer a toll-free telephone number wher ...
's suicide hotline, with LGBTQ rights organization GLAAD criticizing the statement, calling Cloudflare "the definition of hypocrisy" stating that the company is "hiding behind donations to LGBTQ causes and simultaneously refusing to sever ties with he Kiwi Farmswebsite." On September 3, 2022, Cloudflare blocked Kiwi Farms, citing urgent escalating rhetoric against targets of Kiwi Farms, stating that there is an "unprecedented emergency and immediate threat to human life". According to ''The Washington Post'', there was a "surge in credible violent threats stemming from the site" and CEO Matthew Prince said that Cloudflare believes "there is an imminent danger, and the pace at which law enforcement is able to respond to those threats we don't think is fast enough to keep up." Former
whistleblower A whistleblower (also written as whistle-blower or whistle blower) is a person, often an employee, who reveals information about activity within a private or public organization that is deemed illegal, immoral, illicit, unsafe or fraudulent. Whi ...
and
transgender rights A transgender person is someone whose gender identity is inconsistent or not culturally associated with the sex they were assigned at birth and also with the gender role that is associated with that sex. They may have, or may intend to establi ...
activist
Chelsea Manning Chelsea Elizabeth Manning (born Bradley Edward Manning; December 17, 1987) is an American activist and whistleblower. She is a former United States Army soldier who was convicted by court-martial in July 2013 of violations of the Espionage A ...
responded to the situation and said that better long-term solutions are needed for dealing with such "dangerous speech", suggesting an approach that doesn't rely on "hosting providers to have to take these things down".


Terrorism

''The Huffington Post'' has documented Cloudflare's services to "at least 7 terrorist groups", as designated by the
United States Department of State The United States Department of State (DOS), or State Department, is an United States federal executive departments, executive department of the Federal government of the United States, U.S. federal government responsible for the country's fore ...
including the
Taliban The Taliban (; ps, طالبان, ṭālibān, lit=students or 'seekers'), which also refers to itself by its state name, the Islamic Emirate of Afghanistan, is a Deobandi Islamic fundamentalist, militant Islamist, jihadist, and Pasht ...
, Al-Shabaab, the
al-Aqsa Martyrs' Brigades The al-Aqsa Martyrs' Brigades () is a coalition of Palestinian armed groups in the West Bank. The organization has been designated as a terrorist organization by Israel, the European Union, Canada, Japan, New Zealand, and the United States. L ...
,
Hamas Hamas (, ; , ; an acronym of , "Islamic Resistance Movement") is a Palestinian Sunni-Islamic fundamentalist, militant, and nationalist organization. It has a social service wing, Dawah, and a military wing, the Izz ad-Din al-Qassam ...
, Myanmar's military junta led by the
Tatmadaw Tatmadaw (, , ) is the official name of the armed forces of Myanmar (formerly Burma). It is administered by the Ministry of Defence and composed of the Myanmar Army, the Myanmar Navy and the Myanmar Air Force. Auxiliary services include th ...
, and the
al-Quds Brigades Al-Quds Brigades (AQB) ( ar, سرايا القدس, ''Saraya al-Quds'' meaning ''Jerusalem Brigades'') is the armed wing of the Palestinian Islamist organization Palestinian Islamic Jihad (PIJ), which is the second largest group in the Gaza St ...
. Cloudflare has been aware since at least 2012, and has taken no action. However, according to Cloudflare's CEO, no law enforcement agency has asked the company to discontinue these services. Two of the top three online chat forums and nearly forty other web sites belonging to the
Islamic State of Iraq and the Levant An Islamic state is a state that has a form of government based on Islamic law (sharia). As a term, it has been used to describe various historical polities and theories of governance in the Islamic world. As a translation of the Arabic term ...
(ISIL) are guarded by Cloudflare. According to Prince, U.S. law enforcement has not asked Cloudflare to discontinue the service, and it has not chosen to do so itself. In November 2015,
hacktivist In Internet activism, hacktivism, or hactivism (a portmanteau of '' hack'' and '' activism''), is the use of computer-based techniques such as hacking as a form of civil disobedience to promote a political agenda or social change. With roots in h ...
group Anonymous discouraged the use of Cloudflare's services following the ISIL attacks in Paris and additional revelations that Cloudflare aids terrorists. Cloudflare responded by calling the group "15-year-old kids in
Guy Fawkes mask The Guy Fawkes mask (also known as the ''V for Vendetta'' mask or Anonymous mask) is a stylised depiction of Guy Fawkes (the best-known member of the Gunpowder Plot, an attempt to blow up the House of Lords in London on 5November 1605) created ...
s", and saying that whenever such concerns are raised it consults anti-terrorism experts and abides by the law.


Crime

Cloudflare services have been used by Rescator, a carding website that sells stolen payment card data. Cloudflare has been cited in reports by
The Spamhaus Project The Spamhaus Project is an international organisation based in the Principality of Andorra, founded in 1998 by Steve Linford to track email spammers and spam-related activity. The name ''spamhaus'', a pseudo-German expression, was coined by Linf ...
, an international spam tracking organization, for the high numbers of cybercriminal botnet operations hosted by Cloudflare. An October 2015 report found that Cloudflare provisioned 40% of the SSL certificates used by
typosquatting Typosquatting, also called URL hijacking, a sting site, or a fake URL, is a form of cybersquatting, and possibly brandjacking which relies on mistakes such as typos made by Internet users when inputting a website address into a web browser. Shoul ...
phishing Phishing is a type of social engineering where an attacker sends a fraudulent (e.g., spoofed, fake, or otherwise deceptive) message designed to trick a person into revealing sensitive information to the attacker or to deploy malicious softwa ...
sites, which use deceptive domain names resembling those of banks and payment processors to compromise Internet users' banking and other transactions. In 2018, Cloudflare was identified by the European Union's Counterfeit and Piracy Watch List as a "
notorious market A notorious market is a website or physical market where, according to the Office of the United States Trade Representative (USTR), large-scale intellectual property infringement takes place. Officially termed Notorious Markets for Counterfeiting a ...
" which engages in, facilitates, or benefits from counterfeiting and piracy. The report noted that Cloudflare hides and anonymizes the operators of 40% of the world's pirate sites, and 62% of the 500 largest such sites, and "does not follow due diligence when opening accounts for websites to prevent illegal sites from using its services." Italian courts have enjoined Cloudflare to cease hosting pirate television service "IPTV THE BEST" after it was found to be infringing the intellectual property of Sky Italy and the Italian football league, and German courts have similarly found that "Cloudflare and its anonymization services attract structurally copyright infringing websites."


Banning of Switter

In April 2018, Cloudflare dropped Switter as a client and ceased services. Switter was a social media network for the
sex worker A sex worker is a person who provides sex work, either on a regular or occasional basis. The term is used in reference to those who work in all areas of the sex industry.Oxford English Dictionary, "sex worker" According to one view, sex work i ...
community, built on
Mastodon A mastodon ( 'breast' + 'tooth') is any proboscidean belonging to the extinct genus ''Mammut'' (family Mammutidae). Mastodons inhabited North and Central America during the late Miocene or late Pliocene up to their extinction at the end of th ...
's open-source software and was launched in March of 2018, with 49,000 members joining in the first few weeks, before the site was shutdown by Cloudflare. This occurred shortly after the passage of H.R. 1865, FOSTA/SESTA, a set of bills that criminalized websites that "facilitate or support sex trafficking", and was signed into law by President
Donald Trump Donald John Trump (born June 14, 1946) is an American politician, media personality, and businessman who served as the 45th president of the United States from 2017 to 2021. Trump graduated from the Wharton School of the University of P ...
in 2018. According to ''The Verge'', "The conflation of consensual sex work with sex trafficking, as well as the threat of litigation" led to a crackdown by Internet providers. SESTA weakened protections for Internet infrastructure companies and was criticized on free speech grounds due to concerns about disproportionate impact and disruptions to the lives of sex workers. Switter's parent company, Assembly Four, is based in Australia, where sex work has been decriminalized. They had hoped the social media platform would be safe from US legislation, but Cloudflare terminated service, saying the move was "related to our attempts to understand
FOSTA The FOSTA (Allow States and Victims to Fight Online Sex Trafficking Act) and SESTA (Stop Enabling Sex Traffickers Act) are the U.S. Senate and House bills that became law on April 11, 2018. They clarify the country's sex trafficking law to make ...
, which is a very bad law and
ets ETS or ets may refer to: Climate change, environment and economy * Emissions trading scheme ** European Union Emission Trading Scheme Organisations * European Thermoelectric Society * Evangelical Theological Society Education * École de techno ...
a very dangerous precedent". In response, Assembly Four said that "Given Cloudflare's previous stances of privacy and freedom, as well as fighting alongside the
EFF EFF or eff may refer to: Politics * Economic Freedom Fighters, a South African communist political party * Economic Freedom Fund, an American political organization * Election Fighting Fund, a British suffragist organization supporting the ear ...
, we had hoped they would take a stand against FOSTA/SESTA".


Response to the Russian invasion of Ukraine

After Russia invaded Ukraine in late February 2022
Ukrainian Ukrainian may refer to: * Something of, from, or related to Ukraine * Something relating to Ukrainians, an East Slavic people from Eastern Europe * Something relating to demographics of Ukraine in terms of demography and population of Ukraine * So ...
Vice Prime Minister
Mykhailo Fedorov Mykhailo Albertovych Fedorov ( uk, Михайло Альбертович Федоров; born 21 January 1991) is a Ukrainian politician, and businessman currently serving as Vice Prime Minister of Ukraine and Minister of Digital Transformation ...
and others called on Cloudflare to stop providing its services in the
Russian Russian(s) refers to anything related to Russia, including: *Russians (, ''russkiye''), an ethnic group of the East Slavic peoples, primarily living in Russia and neighboring countries *Rossiyane (), Russian language term for all citizens and peo ...
market amidst reports that Russia-linked websites spreading disinformation were using the company’s content delivery network services. Cloudflare CEO Matthew Prince responded that " discriminately terminating service would do little to harm the Russian government but would both limit ussian citizens'access to information outside the country and make significantly more vulnerable those who have used us to shield themselves as they have criticized the government." The company later said it had minimal sales and commercial activity in Russia and had "terminated any customers we have identified as tied to sanctioned entities." Cloudflare's project Galileo, launched in 2014, offers
NGO A non-governmental organization (NGO) or non-governmental organisation (see spelling differences) is an organization that generally is formed independent from government. They are typically nonprofit entities, and many of them are active in h ...
s DDoS protection for free. In 2022, they extended free protection to
Ukrainian government The Cabinet of Ministers of Ukraine ( uk, Кабінет Міністрів України, translit=Kabinet Ministriv Ukrainy; shortened to CabMin), commonly referred to as the Government of Ukraine ( uk, Уряд України, ''Uriad Ukrai ...
and telecoms.


References


External links

* {{Authority control * 2009 establishments in California 2019 initial public offerings American companies established in 2009 Companies based in San Francisco Companies listed on the New York Stock Exchange Content delivery networks DDoS mitigation companies Domain name registrars Freedom of speech in the United States Internet properties established in 2009 Internet security Internet technology companies of the United States Reverse proxy Technology companies based in the San Francisco Bay Area Virtual private network services