All Topics
All Topics
Technology
Technology
AI
AI
Business
Business
Entertainment
Entertainment
News
News
Programming
Programming
Security
Security
Science
Science
Design
Design
Environment
Environment
Finance
Finance
Crypto
Crypto
Politics
Politics
Sports
Sports
Education
Education
Gaming
Gaming
Art
Art
Music
Music
Health
Health
Books
Books
Food
Food
Travel
Travel
Personal
Personal
Bluesky
Twitter

Cloudflare Fundamentals - Automated reminders for backup codes

9mo ago

Source

CloudflareCloudflare Fundamentals - Automated reminders for backup codescloudflare.com
Snippet from the RSS feed
The most common reason users contact Cloudflare support is lost two-factor authentication (2FA) credentials. Cloudflare supports both app-based and hardware keys for 2FA, but you could lose access to your account if you lose these. Over the past few weeks, we have been rolling out email and in-product reminders that remind you to also download backup codes (sometimes called recovery keys) that can get you back into your account in the event you lose your 2FA credentials. Download your backup codes now by logging into Cloudflare, then navigating to Profile > Security & Authentication > Backup codes . Sign-in security best practices Cloudflare is critical infrastructure, and you should protect it as such. Please review the following best practices and make sure you are doing your part to secure your account. Use a unique password for every website, including Cloudflare, and store it in a password manager like 1Password or Keeper. These services are cross-platform and simplify the process of managing secure passwords. Use 2FA to make it harder for an attacker to get into your account in the event your password is leaked Store your backup codes securely. A password manager is the best place since it keeps the backup codes encrypted, but you can also print them and put them somewhere safe in your home. If you use an app to manage your 2FA keys, enable cloud backup, so that you don't lose your keys in the event you lose your phone. If you use a custom email domain to sign in, configure SSO . If you use a public email domain like Gmail or Hotmail, you can also use social login with Apple, GitHub, or Google to sign in. If you manage a Cloudflare account for work: Have at least two administrators in case one of them unexpectedly leaves your company Use SCIM to automate permissions management for members in your Cloudflare account

You might also wanna read

Authentication Reference Implementation for Cloudflare Workers with PBKDF2, JWT Sessions, and NIST Compliance

This article presents a comprehensive authentication reference implementation for Cloudflare Workers that serves as an educational resource

github.com·4mo ago

Cloudflare launches temporary accounts for AI agents to bypass human signup flows

Cloudflare is launching Temporary Accounts for AI agents, allowing them to deploy websites, APIs, and other agents instantly without going t

blog.cloudflare.com·14d ago

Cloudflare launches temporary accounts for AI agents to bypass human signup flows

Cloudflare is launching Temporary Accounts for AI agents, allowing them to deploy websites, APIs, and other agents instantly without going t

Cloudflare·14d ago

Cloudflare Web Bot Auth: Cryptographic Authentication for Automated Bots

Web Bot Auth is an authentication method that uses cryptographic signatures in HTTP messages to verify automated bot requests. It serves as

developers.cloudflare.com·10mo ago

Cloudflare launches self-managed OAuth for all developers with zero-downtime migration

Cloudflare announced the general availability of self-managed OAuth for all developers on its platform, enabling them to create and manage t

Cloudflare·9d ago

Cloudflare launches self-managed OAuth for all developers with zero-downtime migration

Cloudflare announced the general availability of self-managed OAuth for all developers on its platform, enabling them to create and manage t

blog.cloudflare.com·9d ago

Ineffectiveness of Gmail Backup Codes for Account Access

The article discusses the ineffectiveness of Gmail backup codes in accessing an account, despite setting up 2FA and backup codes for securit

news.ycombinator.com·11mo ago

Comments

Sign in to join the conversation.

No comments yet. Be the first.