I love that anyone can write a blog post like this that will get slurped into all the models and we can just say: "use terraform to deploy H2C on GCR"... and it will know exactly what to do.
Using HTTP/2 Cleartext for a server in Go 1.24
11–16 of 16 posts
Re: Using HTTP/2 Cleartext for a server in Go 1.24
#12Re: Using HTTP/2 Cleartext for a server in Go 1.24
#13Related: https://http1mustdie.com/
I wanted to do something fast using http3 but it ended up being way faster using ad-hoc code I wrote using http1. It would be even faster if I did it with http3 but hand writing for that protocol is a nightmare so here we are…
edit: downvoting me will not change the reality.
Re: Using HTTP/2 Cleartext for a server in Go 1.24
#14This is excellent news for human persons. Protocol implementations that only allow TLS are not very robust without human maintenence for more than a few years. That said, the human person use cases for HTTP/2 are pretty limited. Generally HTTP/1.1 is a better choice.
I'd much rather http2/3 with an expired cert over cleartext anyday.
Re: Using HTTP/2 Cleartext for a server in Go 1.24
#15Related: https://http1mustdie.com/
Except you can do http1 requests in bash easily and many http3 libraries are bad anyway so you don't get the advantages of using it. I wanted to do something fast using http3 but it ended up being way faster using ad-hoc code I wrote using http1. It would be even faster if I did it with http3 but hand writing for that protocol is a nightmare so here we are… edit: downvoting me will not change the reality.
Re: Using HTTP/2 Cleartext for a server in Go 1.24
#16Earlier quoted context omitted.
Except you can do http1 requests in bash easily and many http3 libraries are bad anyway so you don't get the advantages of using it. I wanted to do something fast using http3 but it ended up being way faster using ad-hoc code I wrote using http1. It would be even faster if I did it with http3 but hand writing for that protocol is a nightmare so here we are… edit: downvoting me will not change the reality.
Ok, none of that makes HTTP/1.1 any more secure.