The imminent death of HTTP/1.1 and its risks are not understood

4 sam_lowry_ 2 7/22/2025, 9:56:09 AM mikhailian.mova.org ↗

Comments (2)

Arnt · 3h ago
"The last stab in the back are HTTP/1.1 Desync attacks joyfully popularized by James Kettle in DEFCON and Black Hat conferences"

That sounds as if the author thinks http/1.1 is dying because attacks are published. Not because they exist and always have.

sam_lowry_ · 1h ago
It's more about the self-entitlement of security researchers.

And that breaking things is easier than making things.