Settings

Theme

HTTP/1.1 must die: the desync endgame

portswigger.net

17 points by octagons 4 months ago · 2 comments

Reader

1vuio0pswjnm7 4 months ago

"First, HTTP/1.1 is only simple if you're not proxying."

Which is to say, proxy implementations are complex, not HTTP/1.1

"HTTP/2 is not perfect - it's significantly more complex than HTTP/1, and can be painful to implement."

Which is to say, HTTP/2 is complex

Making life easier for (overly) complex proxy software by introducing a more complex protocol

Sounds great

Increasing complexity will surely lead to "a secure web"

JohnMakin 4 months ago

I had heard rumors of this being much worse than I am understanding it. This looks like desync attacks on misconfigured proxies. These misconfigurations are normally assumed benign - which is a problem - but this is nothing all that surprising to me.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection