LendingTree is an online marketplace that enables consumer and business borrowers to connect with multiple lenders to find optimal terms for mortgages, student loans, business loans, credit cards, deposit accounts, and insurance. LendingTree is partnered with over 400 financial institutions worldwide. Over 15 million active users use LendingTree to monitor their credit, shop for loans, and manage their financial health.
When John Turner, Application Security Lead, joined the team at LendingTree, the company was experiencing multiple cost and performance issues with its security vendor. The vendor’s DDoS protection was metered, which caused LendingTree to incur massive overage costs. The solution also blocked legitimate traffic.
“Their solution wasn’t intelligent; it was static,” Turner explains. “We had to manually specify arbitrary limits on requests per minute. Once we exceeded that number, the vendor would offload that traffic, handle it for us, and bill us for the overages.”
These limitations caused significant issues whenever LendingTree launched a marketing campaign. “Whenever we ran a new TV spot or a new social media campaign, requests would spike beyond the arbitrary limit that our vendor had us specify, which meant the vendor would interpret the spike as a DDoS attack and block legitimate traffic,” Turner recalls. “Not only did we lose those potential customers, but we also lost the money that we spent to get them to our site, and our vendor would bill us for the ‘DDoS protection’.”
Turner turned to Cloudflare because of his previous experience working with the company. “In my consulting work, I’ve recommended Cloudflare to clients many times. I knew that Cloudflare’s products worked well and offered a good value,” he says. At LendingTree, Turner decided to implement Cloudflare’s performance and security suites, including Bot Management, WAF, and DDoS protection, along with Workers, Cloudflare's serverless platform.
Cloudflare's DDoS mitigation is unmetered and offers 51 Tbps of mitigation capacity, so LendingTree doesn't have to worry about setting arbitrary traffic limits. LendingTree has also gotten many other security benefits from Cloudflare, including bot management.
Malicious bots that were abusing LendingTree’s APIs were costing the company a lot of money, not only in terms of bandwidth costs but also opportunity cost. Due to the sophistication of the bots and the fact that they were scraping financial data, Turner believed that some of them were being deployed by competitors. LendingTree couldn’t restrict the APIs completely, as its partners needed to be able to access them for current rate information.