Earlier quoted context omitted.
I'm surprised you're surprised. It's a good web server.
I'm surprised HN hasn't added a feature where if you start a comment with "I'm surprised" it asks you to tick a box to confirm that you're really sure you're contributing to the discussion.
Apache HTTP Server 2.4.58 (CVE fixes)
21–30 of 47 posts
Re: Apache HTTP Server 2.4.58 (CVE fixes)
#22Is HTTP/2 just too complex for a mere mortal to implement?
Re: Apache HTTP Server 2.4.58 (CVE fixes)
#23Relevant, HTTP/2 Rapid Reset and Apache https://github.com/icing/blog/blob/main/h2-rapid-reset.md Apache httpd 2.4.58 https://github.com/icing/blog/blob/main/httpd-2.4.58.md
Re: Apache HTTP Server 2.4.58 (CVE fixes)
#24Is HTTP/2 just too complex for a mere mortal to implement?
This attack is just about failing to enforce the negotiated parameters during the start phase of the connection.
Re: Apache HTTP Server 2.4.58 (CVE fixes)
#25Earlier quoted context omitted.
I'm surprised HN hasn't added a feature where if you start a comment with "I'm surprised" it asks you to tick a box to confirm that you're really sure you're contributing to the discussion.
I am strongly in favor of this. I would also like HN to implement a warning that your comment may be extremely uninteresting if it starts out with, "Unfortunately..." or, "Can we all just agree that..."
Re: Apache HTTP Server 2.4.58 (CVE fixes)
#26I'm surprised people still actively use it and it seems on par with nginx, at least according to https://www.netcraft.com/blog/january-2023-web-server-survey...
Why surprised? It's rock solid, stable, fast, and does pretty much everything you need, and nothing is hidden behind premium tiers, unlike nginx where they leave bugs and awful behaviour in the open source version that aren't in the premium ones (e.g. nginx used to only resolve hostname entries on start-up, https://forum.nginx.org/read.php?2,215830,215832#msg-215832 , so if you used a hostname in proxy_pass, and the…
It doesn’t strike me as odd to question its fit for people who have more experience with containers. If there’s a reverse proxy in the front, one may just need business logic in the back.
Re: Apache HTTP Server 2.4.58 (CVE fixes)
#27Earlier quoted context omitted.
Why surprised? It's rock solid, stable, fast, and does pretty much everything you need, and nothing is hidden behind premium tiers, unlike nginx where they leave bugs and awful behaviour in the open source version that aren't in the premium ones (e.g. nginx used to only resolve hostname entries on start-up, https://forum.nginx.org/read.php?2,215830,215832#msg-215832 , so if you used a hostname in proxy_pass, and the…
I love apache as much as anyone, cut my teeth with it and still work with it plenty. It doesn’t strike me as odd to question its fit for people who have more experience with containers. If there’s a reverse proxy in the front, one may just need business logic in the back.
I'm trying to imagine what that haircut would look like
Re: Apache HTTP Server 2.4.58 (CVE fixes)
#28Re: Apache HTTP Server 2.4.58 (CVE fixes)
#29Re: Apache HTTP Server 2.4.58 (CVE fixes)
#30Earlier quoted context omitted.
Why surprised? It's rock solid, stable, fast, and does pretty much everything you need, and nothing is hidden behind premium tiers, unlike nginx where they leave bugs and awful behaviour in the open source version that aren't in the premium ones (e.g. nginx used to only resolve hostname entries on start-up, https://forum.nginx.org/read.php?2,215830,215832#msg-215832 , so if you used a hostname in proxy_pass, and the…
I love apache as much as anyone, cut my teeth with it and still work with it plenty. It doesn’t strike me as odd to question its fit for people who have more experience with containers. If there’s a reverse proxy in the front, one may just need business logic in the back.