|
|
|
|
|
by mittensc
303 days ago
|
|
The article is a nice read on request smuggling. It over-reaches with argument about disallowing http/1.1. Parsers should be better. Moving to another protocol won't solve the issue.
It will be written by the same careless engineers.
So same companies will have the same issues or worse... We just lose readability/debuggability/accesibility. |
|
The post makes the case that HTTP/2 is systematically less vulnerable than HTTP/1 to the kinds of vulnerabilities it's talking about.