3 ms·
Feel free to ask any questions you have. We have quite a few folks from Cloudflare's security team here.
by ejcx 7y ago
Feel free to ask any questions you have. We have quite a few folks from Cloudflare's security team here.
- ignoramous 7y agoVulners.com isn't a free service, are there other cheaper alternatives (perhaps less comprehensive) that maintain database of vulnerabilities? Interestingly, the very impressive infosec people behind Vulners are employed (?) by QIWI, a Russian payments company. That isn't an issue now that you publicly claim to use their service, but were there any reservations raised by legal or otherwise? How much in relative terms were the cost savings when Cloudflare did switch to in-house audits via Flan Scan given the requirements / development / operational / maintenance effort expended + licensing service from Vulners? Does Flan Scan also scan network equipment (like switches, routers etc)? Given the complex heterogeneous nature of the global Cloudflare network, what did the deployment process look like? Will there a follow-up blog post on how that was automated/accomplished? What are the other big cloud / CDN providers doing to scan for vulns / compliance at scale if you're privy to it? Have any of them shown interest in contributing to and/or using Flan Scan? What does the short-term and long-term roadmap for Flan Scan look like? Why "Flan Scan"? :) Thanks a lot.