Cloudflare was founded in July 2009 by
Matthew Prince, Lee Holloway, and
Michelle Zatlyn.[2][8][9] Prince and Holloway had previously collaborated on
Project Honey Pot, a product of Unspam Technologies that served as some inspiration for the basis of Cloudflare.[10] From 2009, the company was venture-capital funded.[11] On August 15, 2019, Cloudflare submitted its
S-1 filing for IPO on the
New York Stock Exchange under the stock ticker NET.[12] It opened for public trading on September 13, 2019 at $15 per share.[13]
In 2020, Cloudflare co-founder and COO Michelle Zatlyn was named president, making her one of the few female presidents of a publicly traded technology company in the U.S.[14]
Cloudflare has acquired web-services and security companies, including StopTheHacker (February 2014),[15] CryptoSeal (June 2014),[16] Eager Platform Co. (December 2016),[17] Neumob (November 2017),[18] S2 Systems (January 2020),[19] Linc (December 2020),[20] Zaraz (December 2021),[21] Vectrix (February 2022),[22]Area 1 Security (February 2022),[23] and BastionZero (May 2024).[24]
Since at least 2017, Cloudflare has been using a wall of
lava lamps in their San Francisco headquarters as a
source of randomness for encryption keys, alongside
double pendulums in its London offices and a
geiger counter in its Singapore offices.[25] The lava lamp installation implements the
Lavarand method, where a camera transforms the unpredictable shapes of the "lava" blobs into a digital image.[26][25]
In Q4 2022,[update] Cloudflare provided paid services to 162,086 customers.[27]
Products
Cloudflare provides network and security products for consumers and businesses, utilizing
reverse proxies for
web traffic, edge computing, and since 2010, a
content distribution network to provide content across its network of servers.[28] It supports web protocols including
SPDY and
HTTP/2,
QUIC, and support for
HTTP/2 Server Push,[29] and in 2022, announced its first
SQL database, D1, which is built on
SQLite.[30] As of 2023,[update] Cloudflare handles an average of 45 million HTTP requests per second.[31]
DDoS mitigation
Cloudflare provides
DDoS mitigation services that protect customers from distributed
denial of service (DDoS) attacks. Cloudflare received media attention in June 2011 for providing DDoS mitigation for the website of
LulzSec, a
black hat hacking group.[32]
In March 2013,
The Spamhaus Project was targeted by a DDoS attack that Cloudflare reported exceeded 300gigabits per second (Gbit/s).[33][34] Patrick Gilmore, of
Akamai, stated that at the time it was "the largest publicly announced DDoS attack in the history of the Internet". While trying to defend Spamhaus against the DDoS attacks, Cloudflare ended up being attacked as well; Google and other companies eventually came to Spamhaus' defense and helped it to absorb the unprecedented amount of attack traffic.[35]
In 2014, Cloudflare began providing free DDoS mitigation for artists, activists, journalists, and human rights groups under the name "Project Galileo".[36] In 2017, they extended the service to electoral infrastructure and political campaigns under the name "Athenian Project".[37][38] By 2020, more than 1,000 users and organizations were participating in Project Galileo, including 31 states.[39][40]
In February 2014, Cloudflare claimed to have mitigated an
NTP reflection attack against an unnamed European customer, which they stated peaked at 400 Gbit/s.[41][42] In November 2014, it reported a 500 Gbit/s DDoS attack in Hong Kong.[43] In July 2021, the company claimed to have absorbed a DDoS attack three times larger than any they'd previously recorded, which their corporate blog implied was over 1.2
Tbit/s in total.[44] In February 2023, Cloudflare reported blocking a 71 million request-per-second DDoS attack which "the company says was the largest HTTP DDoS attack on record".[45]
Edge computing
In 2017, Cloudflare launched Cloudflare Workers, a
serverless computing platform for creating new applications, augmenting existing ones, without configuring or maintaining infrastructure. It has expanded to include Workers KV, a low-latency
key-value data store; Cron Triggers, for scheduling
Cron jobs; and additional tooling for developers to deploy and scale their code across the globe.[46]
Cloudflare and
IBM announced a partnership in August 2023, providing bot management capabilities to protect IBM Cloud customers from malicious bots and automated threats.[47]
Internet security
In April 2020, Cloudflare announced it was moving away from using
reCAPTCHA in favor of
hCaptcha.[48]In September 2022, Cloudflare began to test Turnstile – an alternative to
CAPTCHA. The product, instead of presenting a visual CAPTCHA for the user to solve, automatizes the verification process by conducting JavaScript-based checks inside the browser to determine whether the user is a real person or an automated entity. The algorithm reportedly uses machine learning to optimize the process.[49]
In November 2020, Cloudflare announced Cloudflare for Teams, consisting of a DNS resolver and web gateway called "Gateway", and a
zero-trust authentication service called "Access".[51]
Cloudflare announced a partnership with
PhonePe in January 2023 to secure its mobile payment system.[52] In February, Cloudflare launched Wildebeest to allow
Mastodon users to set up and run their own instances on Cloudflare's infrastructure.[53]
In August 2023, Cloudflare started the Project Cybersafe Schools program as part of a $20 million grant program from
Amazon Web Services, making 70 percent of public school districts in the United States eligible for no-cost cybersecurity services.[54]
SASE
Cloudflare One, the company's overarching
SASE platform, debuted in October 2020.[55]
Cloudflare announced the acquisition of
Area 1 Security in February 2022, a company who developed a product for combating phishing email attacks.[56]
On September 26, 2022, Cloudflare announced Zero Trust SIM, an
eSIM designed to secure mobile devices and prevent
SIM-swapping attacks. The technology is based on the
zero trust security model. According to Cloudflare, the secure eSIM can also be used as a second identification factor with
2FA verification protocols. The product will be first available in the United States, with a planned global rollout in the future.[57][58]
VPN
On September 25, 2019, Cloudflare released a freemium
VPN service for mobile devices called
WARP.[59][60] A year later, beta support for macOS and Windows was released.[61]
Other services
Cloudflare released a beta
Jamstack platform for front-end developers to deploy websites on Cloudflare's infrastructure in December 2020, under the name "Pages".[62] In January 2021, the company began providing its "Waiting Room" digital queue product for free for COVID-19 vaccination scheduling under the title "Project Fair Shot".[63] Project Fair Shot later won a
Webby People's Choice Award in 2022 for Event Management under the Apps & Software category.[64]
In March 2023, Cloudflare announced
post-quantum cryptography will be made freely and forever available to
cloud services, applications and Internet connections.[65] In August, Cloudflare was hired by
SpaceX to boost the performance of
Starlink.[66]
Security and privacy issues
Intrusions
On June 1, 2012, the hacker group
UGNazi redirected visitors to the website
4chan to a Twitter account belonging to UGNazi. They allegedly used
social engineering to trick AT&T support staff into giving them access to Cloudflare CEO Matthew Prince's voicemail, then exploited a vulnerability in Cloudflare's use of Google's two-factor authentication system. Once in control of Prince’s email account, UGNazi was able to redirect the 4chan domain through Cloudflare’s database.[67][68]
Data leaks
From September 2016 until February 2017, a major Cloudflare bug (nicknamed
Cloudbleed) leaked sensitive data, including passwords and authentication tokens, from customer websites by sending extra data in response to web requests.[69] The leaks resulted from a
buffer overflow which occurred, according to numbers provided by Cloudflare at the time, more than 18,000,000 times before the problem was corrected.[70][71]
In May 2017, ProPublica reported that Cloudflare routinely discloses the
names and email addresses of persons complaining about hate sites to the operators of those sites, which has led to the complainants being harassed. In response, Cloudflare's CEO said the company would allow individuals in "certain instances to complain anonymously" and that Cloudflare "would be more selective in its decisions to share with its clients the personal information of people who reported objections".[72]
Service outages
In July 2019, there was a major outage lasting about 30 minutes that was attributed to bad
software deployment.[73][74] In 2020, a misconfiguration of a router caused a data pileup and outage in major European cities.[75] Cloudflare experienced another outage in June 2022.[76]
Controversies
Cloudflare has said that it has a content neutrality policy and that it opposes the policing of its customers on
free speech grounds, except in cases where the customers break the law.[77][78] The company has faced criticism for not banning hate speech websites and websites allegedly connected to terrorism groups,[79] but Cloudflare has maintained that no law enforcement agency has asked the company to discontinue these services and it closely monitors its obligations under U.S. laws.[80]
When asked about whether or not websites should be allowed on Cloudflare, and in response to Twitter remarks by someone from
Anonymous, founder Matthew Prince said he'd "rather take advice from the police or the
U.S. State Department (which is also a customer) than from some faceless Twitter user".[80] Because of its structure and policies, Cloudflare often has people from both sides of an argument asking for websites to be taken down. For example, Anonymous uses Cloudflare for some of its sites, but has pressured Cloudflare to drop other sites, and Cloudflare has also faced pressure from additional groups to take Anonymous sites offline.[80]
In 2022, a research paper by
Stanford University found that Cloudflare was a prominent CDN provider among several other providers that are disproportionately responsible for serving misinformation websites.[81][82]
Service terminations
Cloudflare has come under pressure on multiple occasions due to its services being utilized to serve
far-right content.[83][84][85] As Cloudflare is considered an infrastructure provider, rather than a hosting provider,[failed verification] they have broad legal immunity for the content created by their customers, even in cases of offensive content.[86]
The Daily Stormer
Cloudflare provided DNS routing and DDoS protection for the
white supremacist and
neo-Nazi website, The Daily Stormer. In 2017 Cloudflare
stopped providing its services to The Daily Stormer after an announcement on the website asserted that the "upper echelons" of Cloudflare were "secretly supporters of their ideology".[87][88]
Previously, Cloudflare had refused to take any action regarding The Daily Stormer.[86] Founder Matthew Prince said he found the website's content "vile", but regretted he alone could "decide its fate".[89] He told Business Insider: "The ability of somebody to single-handedly choose to knock content offline doesn’t align with core ideas of due process or justice. Whether that’s a national government launching attacks or an individual launching attacks."[89]
As a self-described "free speech absolutist", Prince, in a blog post, vowed never to succumb to external pressure again and sought to create a "political umbrella" for the future.[86] Prince further addressed the dangers of large companies deciding what is allowed to stay online, a concern that is shared by a number of civil liberties groups and privacy experts.[90][91][92] The
Electronic Frontier Foundation, a US digital rights group, said that services such as Cloudflare "should not be adjudicating what speech is acceptable", adding that "when illegal activity, like inciting violence or defamation, occurs, the proper channel to deal with it is the legal system".[87]
A Cloudflare representative said that the platform "does not host the referenced websites, cannot block websites, and is not in the business of hiding companies that host illegal content".[99] Cloudflare did not terminate service to
8chan until public and legal pressure mounted in the wake of the
2019 El Paso shooting, in which the associated manifesto was published to 8chan.[100][101][102] In an interview with The Guardian immediately after the shooting, CEO Matthew Prince defended Cloudflare's support of 8chan, saying that he had a "moral obligation" to keep 8chan online.[103]
On August 5, 2019, Cloudflare terminated service to 8chan.[104] Following this, 8chan moved its forums from the
clearnet to the
dark web.[105] Cloudflare explained that 8chan "have proven themselves to be lawless and that lawlessness has caused multiple tragic deaths. Even if 8chan may not have violated the letter of the law in refusing to moderate their hate-filled community, they have created an environment that revels in violating its spirit."[106] Prince said that what happened in El Paso was "abhorrent in every possible way", removing 8chan from the Internet was "the right thing to do".[107][103]
In 2022, a campaign was launched by
transgender activist
Clara Sorrenti, who has previously been targeted by the forum, to pressure Cloudflare into terminating service for Kiwi Farms.[123][124] Cloudflare responded by issuing a statement on its abuse policies and saying it didn't want to set precedent for speech on the internet with its "extraordinary" decision.[125]
The company also released a blog post[126] and likened their services to that of a public utility, stating that "Just as the telephone company doesn't terminate your line if you say awful, racist, bigoted things, we have concluded ... that turning off security services because we think what you publish is despicable is the wrong policy", but that it would certainly be the "popular choice" to drop sites that the Cloudflare team "personally feels [are] disgusting and immoral".[127][128] The company also defended their decision by saying that "where they had provided DDoS protection services to an anti-LGBTIQ+ website, they donated 100% of the fees earned to an organisation fighting for
LGBTIQ+ rights".[129] The blog post mentioned Cloudflare's terms of use agreement, which allows them to terminate service due to "content that discloses sensitive personal information, [and] incites or exploits violence against people" but, according to The Guardian, the statement "did not specifically address how Kiwi Farms users doxxing people did not fall foul of these terms".[129]
On September 3, 2022, Cloudflare blocked Kiwi Farms, citing urgent escalating rhetoric against targets of Kiwi Farms, stating that there is an "unprecedented emergency and immediate threat to human life". According to The Washington Post, there was a "surge in credible violent threats stemming from the site" and CEO Matthew Prince said that Cloudflare believes "there is an imminent danger, and the pace at which law enforcement is able to respond to those threats we don't think is fast enough to keep up".[130][131][132]
Cloudflare said the move was "related to our attempts to understand
FOSTA, which is a very bad law and [sets] a very dangerous precedent".[138] Assembly Four said that "Given Cloudflare's previous stances of privacy and freedom, as well as fighting alongside the
EFF, we had hoped they would take a stand against FOSTA/SESTA".[133]
Terrorism
In 2015, testimony to the United States House Committee on Foreign Affairs, it was reported that two of the top three online chat forums and nearly forty other web sites belonging to the
Islamic State of Iraq and the Levant (ISIL) were guarded by Cloudflare.[139]
In September 2019, Cloudflare reported in their
Form S-1 filing that their technology was "used by, or for the benefit of, certain individuals or entities" that were blacklisted due to United States economic and trade sanctions regulations",[141] including "entities identified in OFAC’s counter-terrorism and counter-narcotics trafficking sanctions programs, or affiliated with governments currently subject to comprehensive U.S. sanctions".[142]
Crime
Cloudflare has been cited in reports by
The Spamhaus Project, an international
spam tracking organization, for the high numbers of cybercriminal botnet operations hosted by Cloudflare.[143][144][145] An October 2015 report found that Cloudflare provisioned 40% of the
SSL certificates used by
typosquattingphishing sites, which use deceptive domain names resembling those of banks and payment processors to compromise Internet users' banking and other transactions.[146] Cloudflare has been criticized for having a
conflict of interest by providing DDoS protection to both the operators and victims of "
stresser" services.[147][148]
In 2018, Cloudflare was identified by the European Union's Counterfeit and Piracy Watch List as a "
notorious market" which engages in, facilitates, or benefits from counterfeiting and piracy. The report noted that Cloudflare hides and anonymizes the operators of 40% of the world's pirate sites, and 62% of the 500 largest such sites, and "does not follow due diligence when opening accounts for websites to prevent illegal sites from using its services".[149][150]
In 2020, an Italian court ruled Cloudflare had to block current and future domain names and IP addresses of the pirate IPTV service "IPTV THE BEST" for infringing on Lega
Serie A intellectual property.[151] At the time, Cloudflare was already blocking 22 domain names in Italy.[152] German courts have similarly found that "Cloudflare and its anonymization services attract structurally copyright infringing websites."[153]
Response to the Russian invasion of Ukraine
After
Russia invaded Ukraine in late February 2022,
Ukrainian Vice Prime Minister, Minister of Digital Transformation
Mykhailo Fedorov[154] and others[155] called on Cloudflare to stop providing its services in the
Russian market amidst reports that Russia-linked websites spreading disinformation were using the company’s content delivery network services.[156] Cloudflare CEO Matthew Prince responded that the company decided to remain providing services to Russian people to counter Russia's attempts to raise a 'digital iron curtain'.[157][158] Prince shared that "Indiscriminately terminating service would do little to harm the Russian government but would both limit [Russian citizens'] access to information outside the country and make significantly more vulnerable those who have used us to shield themselves as they have criticized the government."[159] The company later said it had minimal sales and commercial activity in Russia and had "terminated any customers we have identified as tied to sanctioned entities".[160]
Cloudflare's project Galileo, launched in 2014, offers
NGOs DDoS protection for free. In 2022, they extended free protection to
Ukrainian government and telecoms.[161][162]
^"What is a reverse proxy? Proxy servers explained". Cloudflare. Retrieved September 2, 2022. A reverse proxy is a server that sits in front of web servers ... typically implemented to help increase security, performance, and reliability.