/plushcap/analysis/cloudflare/require-hard-key-auth-with-cloudflare-access

Require hard key auth with Cloudflare Access

What's this blog post about?

In August 2020, Twitter faced a security breach where attackers compromised an internal administrative panel to take over high-profile accounts. The attackers used spear phishing to steal credentials and access the Twitter control plane. This incident highlights the risk of using administrative panels as they can be targeted by phishing attacks. To prevent such incidents, Cloudflare has implemented several safeguards including hard keys for team members who need to access their admin panel. They also use Cloudflare Access to enforce the use of hard keys and limit access to specific users in permission groups. This zero-trust approach ensures that only authorized personnel can access sensitive systems and data, reducing the risk of security breaches.

Company
Cloudflare

Date published
Aug. 20, 2020

Author(s)
Sam Rhea

Word count
1474

Hacker News points
3

Language
English


By Matt Makai. 2021-2024.