From Wikipedia, the free encyclopedia
  (Redirected from CloudFlare)
Jump to navigation Jump to search
Cloudflare, Inc.
Cloudflare logo.svg
FoundedJuly 2009; 10 years ago (2009-07)
  • Matthew Prince
  • Lee Holloway
  • Michelle Zatlyn
Key people
  • Matthew Prince (CEO)
  • Lee Holloway
  • Michelle Zatlyn
Alexa rankPositive decrease 1056 (February 2019)[1]

Cloudflare, Inc. is a U.S. company that provides content delivery network services, DDoS mitigation, Internet security and distributed domain name server services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites. Cloudflare's headquarters are in San Francisco, California, with additional offices in Lisbon[2], London, Singapore, Munich, San Jose, Champaign, Austin, New York and Washington, D.C.[3][4]


Cloudflare was created in 2009 by Matthew Prince, Lee Holloway, and Michelle Zatlyn,[5][6] who had previously worked on Project Honey Pot.[6][7] Cloudflare was launched at the September 2010 TechCrunch Disrupt conference.[5][6] It received media attention in June 2011, after providing security to LulzSec's website.[5][8]

In June 2012, Cloudflare partnered with various web hosts, including HostPapa, to implement its "Railgun" technology.[9][10]

In February 2014, Cloudflare mitigated the largest-ever recorded DDoS attack at that time, which peaked at 400 Gbit/s against an undisclosed customer.[11] In November 2014, Cloudflare reported another massive DDoS attack with independent media sites being targeted at 500 Gbit/s.[12]

Funding rounds[edit]

In November 2009, Cloudflare raised $2.1 million in a Series A round from Pelion Venture Partners and Venrock.[13]

In July 2011, Cloudflare raised $20 million in a Series B round from New Enterprise Associates, Pelion Venture Partners, Venrock.[13][14][15]

In December 2012, Cloudflare raised $50 million in a Series C round from New Enterprise Associates, Pelion Venture Partners, Venrock, Union Square Ventures, and Greenspring Associates.[16][17][18]

In December 2014, Cloudflare raised $110 million in a Series D round led by Fidelity Investments, with participation from Google Capital, Microsoft, Qualcomm, and Baidu.[19]

In March 2019, Cloudflare raised $150 million in a Series E round led by Franklin Templeton Investments, with participation from New Enterprise Associates, Union Square Ventures, Venrock, Pelion Venture Partners, Greenspring Associates, CapitalG, Microsoft, Baidu, Qualcomm and Fidelity.[20]


In February 2014, it acquired StopTheHacker, which offers malware detection, automatic malware removal, and reputation and blacklist monitoring.[21][22] In December 2016, Cloudflare acquired Eager, with the view of upgrading Cloudflare's Apps platform to allow for drag-and-drop of installation of third-party apps onto Cloudflare-enabled sites.[23] In late 2017, Cloudflare acquired Neumob, a mobile VPN startup.[24]


DDoS protection[edit]

For all customers Cloudflare offers an "I'm Under Attack" mode. Cloudflare claims this can mitigate advanced Layer 7 attacks by presenting a JavaScript computational challenge which must be completed by a user's browser before the user can access a website.[25]

In March 2013, Cloudflare defended SpamHaus from a DDoS attack that exceeded 300 Gbit/s. Akamai's chief architect stated that at the time it was "the largest publicly announced DDoS attack in the history of the Internet".[26][27] Cloudflare has also reportedly absorbed attacks that have peaked over 400Gbit/s from an NTP Reflection attack.[28]

Web application firewall[edit]

Cloudflare allows customers on paid plans to utilize a web application firewall service, by default; the firewall has the OWASP ModSecurity Core Rule Set alongside Cloudflare's own ruleset and rulesets for popular web applications.[29]

Authoritative DNS[edit]

Cloudflare offers free authoritative Domain Name System (DNS) service for all clients which are powered by an anycast network.[30] SolveDNS have found Cloudflare to consistently have one of the fastest DNS lookup speeds worldwide, with a reported lookup speed of 8.66ms in April 2016.[31]

Public DNS resolver[edit]

On April 1, 2018, Cloudflare announced a 'privacy-first' consumer DNS service, hosted at IP addresses and Alternatively, the service can be accessed via IPv6 at 2606:4700:4700::1111 and 2606:4700:4700::1001.[32][33]

On November 11, 2018, Cloudflare announced a mobile version of their service for iOS and Android.[34]

Reverse proxy[edit]

A key functionality of Cloudflare is that they act as a reverse proxy for web traffic.

Cloudflare supports new web protocols, including SPDY and HTTP/2. In addition to this, Cloudflare offers support for HTTP/2 Server Push.[35] Cloudflare also supports proxying WebSockets.

Content delivery network[edit]

Cloudflare's network has the highest number of connections to Internet exchange points of any network worldwide.[36] Cloudflare caches content to its edge locations to act as a content delivery network (CDN), all requests are then reverse proxied through Cloudflare with cached content served directly from Cloudflare.

Project Galileo[edit]

In 2014, Cloudflare introduced Project Galileo in response to cyber attacks launched against important, yet vulnerable targets, such as artistic groups, humanitarian organizations, and the voices of political dissent. Working with free speech, public interest, and civil society organizations, Cloudflare then extended its Enterprise-class DDoS protection and business-level performance benefits to ensure these websites stay online, without being violated.

Project Athenian[edit]

Cloudflare created Project Athenian to ensure that state and local government election websites have the highest level of protection (Enterprise grade) and reliability for free, so that their constituents always have access to election information and voter registration.[citation needed]

Domain Registrar[edit]

In 2019, Cloudflare announced a new domain registrar service that promised to offer low-cost wholesale pricing and easy ways to enable DNSSEC.


On April 1, 2019 Cloudflare announced a new freemium Virtual Private Network service named Warp. The service would initially be available through the mobile apps with a desktop app available later.[37]

Network Time Services[edit]

On June 21, 2019 Cloudflare announced that users would be able to sync their computers time securely with Cloudflare's NTP service. Cloudflare’s time service will allow users to connect to their Network Time Protocol (NTP) server that supports Network Time Security (NTS), enabling users to obtain time in an authenticated manner.[38]


As of 2017, Cloudflare provides DNS services to 12 million websites,[39] adding approximately 20,000 new customers every day.[40] 

Awards and recognition[edit]

Content neutrality[edit]

Cloudflare has been vocal of their values, with CEO Matthew Prince stating:

One of the greatest strengths of the United States is a belief that speech, particularly political speech, is sacred. A website, of course, is nothing but speech ... A website is speech. It is not a bomb. There is no imminent danger it creates and no provider has an affirmative obligation to monitor and make determinations about the theoretically harmful nature of speech a site may contain.[46]

Cloudflare services have been used by Rescator, a website that sells payment card data.[47][48][49]

Two of Islamic State of Iraq and the Levant's top three online chat forums are guarded by Cloudflare but U.S. law enforcement has not asked them to discontinue the service, and they have not chosen to do so themselves.[50]

In November 2015, Anonymous discouraged the use of Cloudflare's services, following the ISIL attacks in Paris and the renewed accusation that it provides help to terrorists.[51] Cloudflare responded by calling their accusers "15-year-old kids in Guy Fawkes masks" and saying that whenever such concerns are raised they consult actual anti-terrorism experts and abide by the law.[52]

Breaking with its long-standing policy of total content neutrality, Cloudflare withdrew access to its services by white supremacist web site The Daily Stormer on 16 August 2017, in the aftermath of the fatal vehicular attack at the Charlottesville rally four days earlier. This withdrew the website's protection against distributed denial of service attack, and soon thereafter attackers took down the website.[53] CEO Matthew Prince stated: "I woke up this morning in a bad mood and decided to kick them off the internet",[54] the tipping point in the decision being "that the team behind Daily Stormer made the claim that we were secretly supporters of their ideology."[55][56] Andrew Anglin, editor for The Daily Stormer, denied that his team made such a claim, and the move to disconnect The Daily Stormer from Cloudflare services was criticised as 'dangerous' by Prince himself,[57][58] Anglin,[59] and the Electronic Frontier Foundation.[60]


The hacker group UGNazi attacked Cloudflare partially via flaws in Google's authentication systems in June 2012, gaining administrative access to Cloudflare and using it to deface 4chan.[61][62] Cloudflare published in full the details of the hack. Following this, Google publicly announced they had patched the flaw in the Google Enterprise App account recovery process which allowed the hackers to bypass two-step verification.[63]

From September 2016 until February 2017, a major Cloudflare bug (nicknamed Cloudbleed) leaked sensitive data—including passwords and authentication tokens from customer websites, by sending extra data in response to web requests.[64] The leaks resulted from a buffer overflow, which occurred, according to analysis by Cloudflare, on approximately 1 in every 3,300,000 HTTP requests.[65][66]


Cloudflare publishes a Transparency Report on a semiannual basis to show how often law enforcement agencies request data about its clients.[67]

In May 2017, ProPublica reported that Cloudflare as a matter of policy relays the names and email addresses of persons complaining about hate sites to the sites in question, which has led to the complainants being harassed. Cloudflare's general counsel defended the company's policies by saying it is "base constitutional law that people can face their accusers."[68] In response Cloudflare updated their abuse reporting process to provide greater control of whom to notify for the complaining party.[69]

Spam and phishing support[edit]

Cloudflare is listed on Spamhaus for providing spam support services (pink contract). The current list of Spamhaus listings changes on a near daily basis as reported issues are addressed with the responsible website owner.[70][71]

An October 2015 report found that Cloudflare provisioned 40% of SSL certificates used by phishing sites with deceptive domain names resembling those of banks and payment processors.[72]


In July 2019 Cloudflare suffered a major outtake, which rendered more than 12 million websites unreachable for 27 minutes (80% of all customers)[73][74]. The affected websites responded with a blank 502 Error Page[75]. Cloudflare published internal investigation results[76], in which the cause of the outtake was pinpointed to a faulty Regular_expression.


  1. ^ " Traffic, Demographics and Competitors". Alexa Internet. Retrieved 2019-02-26.
  2. ^ "Cloudflare's new Lisbon office". The Cloudflare Blog. 2019-07-17. Retrieved 2019-07-22.
  3. ^ "Cloudflare Reveals $50 Million "Secret" Funding -- From One Year Ago - Kara Swisher - Security - AllThingsD". AllThingsD.
  4. ^ "Cloudflare beefs up app platform plans with startup acquisition". Retrieved 2017-02-28.
  5. ^ a b c Henderson, Nicole (2011-06-17). "Cloudflare Gets an Unusual Endorsement from Hacker Group LulzSec". Webhost Industry Review. Retrieved 2014-05-09.
  6. ^ a b c "Our story". Cloudflare. Retrieved 2016-02-25.
  7. ^ "Cloudflare Beta". Project Honey Pot. Retrieved 2011-08-15.
  8. ^ Hesseldahl, Arik (2011-06-10). "Web Security Start-Up Cloudflare Gets Buzz, Courtesy of LulzSec Hackers". All Things Digital. Retrieved 2011-08-15.
  9. ^ Clark, Jack (1 March 2013). "Cloudflare's Railgun protocol gets buy-in from web giants". The Register. Retrieved 8 October 2015.
  10. ^ Lardinois, Frederic (26 February 2013). "Cloudflare Partners With World's Leading Web Hosts To Implement Its Railgun Protocol, Speeds Up Load Times By Up To 143%". Tech Crunch. Retrieved 12 February 2016.
  11. ^ "DDoS Attack Hits 400 Gbit/s, Breaks Record". Dark Reading.
  12. ^ Olson, Parmy. "The Largest Cyber Attack In History Has Been Hitting Hong Kong Sites". Forbes.
  13. ^ a b [1]
  14. ^ Hesseldahl, Arik (2011-07-12). "Web Security Start-Up Cloudflare Lands $20 Million Funding Round". AllThingsD. Retrieved 2012-07-12.
  15. ^ Milian, Mark (December 18, 2012). "Why a Fast-Growing Startup Tries to Keep Its Venture Funding Secret". Tech Deals. Bloomberg. Retrieved January 1, 2013.
  16. ^ "Cloudflare Reveals $50M Round From Union Square Ventures". TechCrunch. AOL.
  17. ^ Michael Hickins. "Cloudflare Raised $50M, Ready to Spend". WSJ.
  18. ^ "Cloudflare Reveals $50M Round From Union Square Ventures". TechCrunch. AOL. 17 December 2013.
  19. ^ Miller, Ron. "Cloudflare Hints IPO Could Be Coming, But Not This Year". Retrieved 30 September 2015.
  20. ^ Kawamoto, Dawn. "Cloudflare's $150 million funding round puts its IPO plans in question". Retrieved 12 March 2019.
  21. ^ "CryptoSeal". Retrieved 10 March 2015.
  22. ^ "Cloudflare Acquires Anti-Malware Firm StopTheHacker". TechCrunch. AOL.
  23. ^ Yeung, Ken. "Cloudflare acquires app platform Eager, will sunset service in Q1 2017". VentureBeat. Retrieved 28 December 2016.
  24. ^ Miller, Ron (November 14, 2017). "Cloudflare expands into mobile performance with Neumob acquisition". TechCrunch. Archived from the original on December 3, 2018. Retrieved April 2, 2019.
  25. ^ Holloway, Lee Hahn; Rao, Srikanth N.; Prince, Matthew Browning; Tourne, Matthieu Philippe François; Pye, Ian Gerald; Bejjani, Ray Raymond; Rodery Jr, Terry Paul (2013). "Identifying a denial-of-service attack in a cloud-based proxy service".
  26. ^ Storm, Darlene. "Biggest DDoS attack in history slows Internet, breaks record at 300 Gbps". Computerworld.
  27. ^ Markoff, John; Perlroth, Nicole (26 March 2013). "Online Dispute Becomes Internet-Snarling Attack". The New York Times.
  28. ^ Gallagher, Sean. "Biggest DDoS ever aimed at Cloudflare's content delivery network". Ars Technica. Retrieved 17 May 2016.
  29. ^ Kaushik, Mehul. "Cloudflare Web Application Firewall Review". Fanatic Entrepreneur. Archived from the original on 2017-04-08. Retrieved 2017-04-07.
  30. ^ Jackson, Brian (17 September 2015). "10 Best Free DNS Hosting Providers". KeyCDN Blog. Retrieved 17 May 2016.
  31. ^ "April 2016 DNS Speed Comparison Report".
  32. ^ "Anouncing the fastest, privacy-first consumer DNS service". Cloudflare. 1 April 2018.
  33. ^ "Cloudflare Launches Privacy-Focused DNS Service". Tom's Hardware. 2 April 2018.
  34. ^ Cimpanu, Catalin. "Cloudflare launches Android and iOS apps for its service | ZDNet". ZDNet.
  35. ^ Osborne, Charlie. "Cloudflare figured out how to make the Web one second faster | ZDNet". ZDNet. Retrieved 17 May 2016.
  36. ^ "Internet Exchange Report -". Hurricane Electric. Retrieved June 1, 2016.
  37. ^ Rambo, Guilherme (April 1, 2019). "Cloudflare announces Warp: a new free VPN service for iOS". 9to5Mac. Archived from the original on April 2, 2019. Retrieved April 2, 2019.
  38. ^ "Cloudflare Time Services". Cloudflare. Retrieved 2019-06-22.
  39. ^ "How we made our DNS stack 3x faster". Retrieved 2017-04-11.
  40. ^ "Cloudflare – Making Your Website Fast, Safe, and Accessible Everywhere in the World | HostAdvice". HostAdvice. Retrieved 2017-07-19.
  41. ^ "8th Annual Crunchies Awards". TechCrunch. AOL. Retrieved 10 March 2015.
  42. ^ Michael Totty and Shirley S. Wang (17 October 2011). "Winners of the 2011 Wall Street Journal Innovation Awards - WSJ". WSJ. Retrieved 10 March 2015.
  43. ^ "Technology Pioneer 2012 - Matthew Prince, Michelle Zatlyn & Lee Holloway (Cloudflare)". Technology Pioneer 2012 - Matthew Prince, Michelle Zatlyn & Lee Holloway (Cloudflare) - World Economic Forum. Retrieved 10 March 2015.
  44. ^ "Most Innovative Companies 2012 - Industries Top 10 - Web/Internet". Fast Company. Retrieved 10 March 2015.
  45. ^ "Forbes Cloud 100". Forbes. Retrieved 6 May 2017.
  46. ^ Dredge, Stuart (12 August 2013). "Cloudflare on censorship: 'A website is speech. It is not a bomb'". the Guardian.
  47. ^ Yadron, Danny (29 September 2014). "Cloudflare Pushes More Encrypted Web". Retrieved 10 August 2015.
  48. ^ Kovacs, Eduard (17 March 2014). "Underground Payment Card Store Rescator Hacked and Defaced". Retrieved 10 August 2015.
  49. ^ Krebs, Brian (15 January 2015). "Spreading the Disease and Selling the Cure". Retrieved 14 August 2015.
  50. ^ "Testimony of Evan F. Kohlmann" (PDF). 27 January 2015.
  51. ^ Hern, Alex (19 November 2015). "Web services firm Cloudflare accused by Anonymous of helping Isis". Retrieved 19 November 2015.
  52. ^ "Cloudflare CEO: Anonymous Hacker Gripes About ISIS Support 'Absurd'". Retrieved 2017-02-28.
  53. ^ Becky Peterson (17 August 2017). "Cloudflare CEO: Hackers pushed The Daily Stormer offline as soon as Cloudflare stopped protecting it". Business Insider. Retrieved 17 August 2017.
  54. ^ David Ingram and Joseph Menn (17 August 2017). "Internet firms shift stance, move to exile white supremacists". Reuters. Retrieved 17 August 2017.
  55. ^ Dave Lee (17 August 2017). "Why Cloudflare kicked out the neo-Nazis". BBC News. Retrieved 17 August 2017.
  56. ^ Matthew Prince (17 August 2017). "Why We Terminated Daily Stormer". Cloudflare blog. Retrieved 17 August 2017.
  57. ^ "The Daily Stormer just lost the most important company defending it". The Verge. Retrieved 2018-03-23.
  58. ^ Johnson, Steven. "Inside Cloudflare's Decision to Let an Extremist Stronghold Burn". WIRED. Retrieved 19 March 2018.
  59. ^ Andrew Anglin (17 August 2017). "Matthew Prince of Cloudflare Admits He Killed the Internet Because He Thinks Andrew Anglin is an Asshole". The Daily Stormer. Archived from the original on 18 August 2017. Retrieved 17 August 2017.
  60. ^ O'Brien, Jeremy Malcolm, Cindy Cohn, and Danny (2017-08-17). "Fighting Neo-Nazis and the Future of Free Expression". Electronic Frontier Foundation. Retrieved 2018-03-23.
  61. ^ Simcoe, Luke (2012-06-14). "The 4chan breach: How hackers got a password through voicemail". Maclean's. Retrieved 2012-07-12.
  62. ^ Ms. Smith (2012-06-03). "Hacktivists UGNazi attack 4chan, Cloudflare and Wounded Warrior Project". Privacy and Security Fanatic. NetworkWorld. Retrieved 2012-07-12.
  63. ^ Prince, Matthew (4 June 2012). "The Four Critical Security Flaws that Resulted in Last Friday's Hack". Cloudflare.
  64. ^ "Major Cloudflare bug leaked sensitive data from customers' websites". TechCrunch. 2017-02-23. Retrieved 2017-02-28.
  65. ^ Joseph Steinberg (February 24, 2017). "Why You Can Ignore Calls To Change Your Passwords After Today's Massive Password Leak Announcement". Inc. Retrieved February 24, 2017.
  66. ^ Molina, Brett (February 28, 2017). "Cloudfare bug: Yes, you should change your passwords". USA Today. Retrieved 1 March 2017.
  67. ^ Kovacs, Eduard (2015-07-15). "Cloudflare Releases Transparency Report for First Half of 2015 | SecurityWeek.Com". Wired Business Media.
  68. ^ Schwencke, Ken (May 4, 2017). "How One Major Internet Company Helps Serve Up Hate on the Web". Retrieved 6 May 2017.
  69. ^ Anonymity and Abuse Reports
  70. ^ "Cloudflare and Spamhaus". Word to the Wise. 2012-07-16. Retrieved 2017-02-28.
  71. ^ The Spamhaus Project:
  72. ^ Edgecombe, Graham (12 October 2015). "Certificate authorities issue SSL certificates to fraudsters". Retrieved 14 October 2015.
  73. ^ "Details of the Cloudflare outage on July 2, 2019". 12 July 2019. Retrieved 12 July 2019.
  74. ^ "Cloudflare Landing Page". 15 July 2019. Retrieved 15 July 2019.
  75. ^ "Cloudflare 502 Outtake". 2 July 2019. Retrieved 2 July 2019.
  76. ^ "Details of the Cloudflare outage on July 2, 2019". 12 July 2019. Retrieved 12 July 2019.

External links[edit]