HTTP/1.1 must die: the desync endgame

5 octagons 1 8/7/2025, 2:12:27 AM portswigger.net ↗

Comments (1)

1vuio0pswjnm7 · 1h ago
"First, HTTP/1.1 is only simple if you're not proxying."

Which is to say, proxy implementations are complex, not HTTP/1.1

"HTTP/2 is not perfect - it's significantly more complex than HTTP/1, and can be painful to implement."

Which is to say, HTTP/2 is complex

Making life easier for (overly) complex proxy software by introducing a more complex protocol

Sounds great

Increasing complexity will surely lead to "a secure web"