Skip to content

Comment on HTTP/1.1 must die: the desync endgameparent

Comments

The new features/behaviors in the new protocol inherently create new classes of vulnerabilities. That above link relates to an issue with RST_STREAM frames. You can't have issues with frames if you lack frames.

It's quite possible the old issues are worse than the new ones, but it's not obvious that's the case.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.