Taiwan Tati Cultural and Educational Foundation

 
  • Increase font size
  • Default font size
  • Decrease font size
Home Editorials of Interest Taipei Times Lessons from the Cloudflare crash

Lessons from the Cloudflare crash

On Tuesday last week at 7:30pm, Cloudflare, the world’s largest Internet infrastructure provider offering Web security and traffic acceleration services, had a major crash.

The outage brought down critical online services worldwide, including several essential public and government Web sites in Taiwan, for 45 minutes. The incident was no minor network glitch — it was a serious reminder of digital national security concerns, a global issue Taiwan must be especially alert of.

Having long been a target of Chinese cyberattacks, Taiwan’s dependence on Cloudflare is very risky. The risks include distributed denial-of-service attacks, in which targets are flooded with junk traffic from multiple sources to paralyze the Web site.

Cloudflare provides a shield against such attacks, so it is used by many government agencies, social media platforms, payment service providers, e-commerce sites and artificial intelligence platforms in Taiwan as a first line of defense.

As a result, Taiwan’s Internet security increasingly relies on a single company. Cloudflare also provides an entire ecosystem of Web infrastructure on which Taiwan depends. These include content delivery networks (CDN) for faster Web performance, web application firewalls (WAF) to protect against cyberattacks and malicious traffic, domain name system (DNS) services to translate Web site addresses into IP addresses, reverse proxy servers which sit between a Web site and its visitors to filter user requests, and edge points-of-presence (PoP) where network access points are hosted at physical locations closer to end-users.

A malfunction of any of these services is enough to shut down a significant number of Taiwanese Web sites. Last week’s crash made it clear that Taiwan cannot afford for Cloudflare to fail. This represents a serious geopolitical risk. Cloudflare houses a major edge PoP in Taipei for processing local Web traffic.

Lying well within China’s potential range of attack, if it were targeted or disabled in a conflict, there would be no need to attack Taiwanese servers directly. Taking out that node alone could paralyze government Web sites, payment application programming interfaces (APIs), public service portals, news platforms, and medical and transport information systems simultaneously.

Network breakages are the fastest, most cost-effective and efficient weapons of information warfare. Yet, local government, central ministries and public service platforms all rely on Cloudflare’s firewall, CDN and Reverse Proxy services for speed and security — these act to screen and filter incoming Web traffic and user requests, distinguishing between advertisers, potential cyberattacks and ordinary users.

If this frontline guardrail falls, Taiwan’s government Web sites go down with it. To prevent the nation from becoming a victim of its overdependency, there are three reforms it could apply to level up digital national security.

First, government and critical infrastructure must adopt a multi-vendor architecture approach to Web operations. There must be at least two functional sets of CDN, DNS, WAF and edge PoP systems that can switch over automatically in the event of an outage. This would mean that if Cloudflare fails, traffic is rerouted to the “failover” system.

Second, Taiwan must develop national CDN and DNS systems that do not rely on private companies or foreign servers for government and public service Web infrastructure. Critical information systems must be localized to insulate against the effects of network failures overseas. Estonia and Israel already have such systems in place. Taiwan cannot afford to fall further behind.

Third, a wartime digital resilience plan that includes interregional backups of government information systems, such as mirror Web sites hosted offshore or overseas, must be established. Essential APIs for power, healthcare and transportation should be decoupled, and emergency broadcast channels must be established for when the Internet is down.

Each of these are essential measures of modern national security, and in a crisis, lives would depend on it.

The Cloudflare crash was a test case. Next time, the outage might not be due to a system error, but a cyberattack. It might not last just 45 minutes, but four or five hours.

In the face of rising authoritarianism, great powers could turn to militarization, but small countries must rely on resilience. Taiwan must reclaim control over its critical Web infrastructure and ensure that, in the event of future shocks, it cannot be so easily toppled.

Hsiao Hsi-huei is a freelance writer.

Translated by Gilda Knox Streader


Source: Taipei Times - Editorials & Opinion 2025/11/25



Add this page to your favorite Social Bookmarking websites
Reddit! Del.icio.us! Mixx! Google! Live! Facebook! StumbleUpon! Facebook! Twitter!  
 

Newsflash


Professor Hsu Shih-jung of National Chengchi University shows his bruises during a press conference at the Legislative Yuan yesterday. The bruises were caused when he was arrested during a protest against the Dapu houses-demolition case.
Photo: Liao Chen-huei, Taipei Times

A university professor who was arrested on Tuesday during a protest over the forced demolition of houses in Dapu Borough (大埔) in Miaoli County’s Jhunan Township (竹南) accused national security authorities of instructing police to use excessive force against protesters and urged President Ma Ying-jeou’s (馬英九) administration to stop enforcing repressive controls over its people.

“Most of Taipei City’s police officers were nice to me and I believe they were forced by national security authorities to handle the protest with violence. It’s the national security authorities that are uncivilized,” National Chengchi University professor Hsu Shih-jung (徐世榮) said at the Taipei City Council.