Cloudflare Introduces the Industry's First Security-Focused Registrar
Designed for Security, Not the Masses, Cloudflare Registrar Is the first ICANN-Accredited Registrar Built for High-Profile Domains
SAN FRANCISCO, CA--(Marketwired - Feb 23, 2016) - Cloudflare, the leading Internet performance and security company, today launched Cloudflare Registrar, to bring large enterprises the highest level of security available and to protect their web domains from unauthorized changes. One of the biggest risks for high-profile customers is having their domains hijacked -- meaning their sites are redirected or compromised without the site owner's approval. Now, domain hijacking, domain expiration, or loss of control over an external account are all prevented with Cloudflare Registrar.
The security of a domain name is only as robust as the security of the registrar used to maintain it. Many domains on the Internet, even the highest-value domains belonging to large household name brands, are managed through consumer-focused registrars with limited security features. Domain hijacks -- whether they are conducted by third party attackers or rogue employees -- can be difficult to detect. What's more, reclaiming a domain can be an arduous, expensive, reputation-damaging process that is never guaranteed.
"Customers who care enough about the security of their website to use Cloudflare are still at risk to domain hijacking via their registrar. By offering registrar services to Cloudflare Enterprise customers, we instantly eliminate the additional risk a third-party registrar may overlook," said Matthew Prince, co-founder and CEO of Cloudflare. "Even in Cloudflare's own search for a high-security registrar, we didn't find anything that met our security standard. Rather than waiting for one to come onto the market, we built our own, fundamentally changing the way Registrar security is offered today."
With Cloudflare Registrar, owners of high-value domains can protect themselves with enterprise-grade, customizable domain security and integrate domain renewal into their IT department workflow. This protects enterprises from the unexpected consequence of losing their domain, resulting in damage to their brand's reputation, complete loss of their security functionality, control over their website's content, and the potential to redirect web traffic to another IP address.
While domain hijacks have historically been outright web defacements or theft, an attacker can also choose to be more subtle and proxy traffic to the original server, observing every user and tampering with any target. This is a particular risk for API providers (such as mobile application or IoT backends), where the hijacking of a domain can remain undetected while being exploited to compromise many applications.
Rather than limiting registrar account security to a single shared password or email address, customers can now require formal approval from multiple independent stakeholders within the organization to make any change. By adding friction to the process, it prevents the worst-case consequences of domain compromise. Web properties using Cloudflare Registrar will never expire; all domains will automatically renew when they have less than one year left on their registration term.
Domain name registrars, registry operators, and the governing body ICANN have developed various security measures to protect domains and registrants -- but they have not been widely implemented. "With other technologies like certificates, if anyone trusted is compromised, everyone is at risk. DNS isn't like that, you can manage your risk by choosing which registrar you trust. And the risk is significant; networks can be no safer than the DNS infrastructure that links them. Cloudflare integrating registrar security into their broad product line reflects a commitment to a deep level of security on the public Internet," said Dan Kaminsky, DNS security expert and chief scientist and co-founder of White Ops.
"Cloudflare Registrar isn't for the masses, it's for organizations that would make a front-page story if they lost their domains," Prince said. "There are plenty of great mass-market registrars available today, but now high-profile organizations don't need to settle for a one-size-fits-most security approach when it comes to their online brands."
Interested Cloudflare Enterprise customers should contact their dedicated account managers to get started with Cloudflare Registrar. If you are not a current customer, learn how Cloudflare can help fully lock down your domains today.