[flagged]
haproxy mitigated this attack in 2018 as an implementation bug: https://news.ycombinator.com/item?id=37833365
HAProxy is not affected by the HTTP/2 Rapid Reset Attack
21–30 of 36 posts
Re: HAProxy is not affected by the HTTP/2 Rapid Reset Attack
#22I'm quite impressed with HAProxy. It takes a little effort to fully understand the configuration file format (hint: you've got to read the documentation, not just look at examples to fully grok it), but it's so worth it, IMO. It's also a nice treat to have the founder and technical leader (Willy Tarreau) of the HAProxy company being so active in the community, so many years later (the initital release was in 2001). I…
Re: HAProxy is not affected by the HTTP/2 Rapid Reset Attack
#23I'm quite impressed with HAProxy. It takes a little effort to fully understand the configuration file format (hint: you've got to read the documentation, not just look at examples to fully grok it), but it's so worth it, IMO. It's also a nice treat to have the founder and technical leader (Willy Tarreau) of the HAProxy company being so active in the community, so many years later (the initital release was in 2001). I…
Re: HAProxy is not affected by the HTTP/2 Rapid Reset Attack
#24I'm quite impressed with HAProxy. It takes a little effort to fully understand the configuration file format (hint: you've got to read the documentation, not just look at examples to fully grok it), but it's so worth it, IMO. It's also a nice treat to have the founder and technical leader (Willy Tarreau) of the HAProxy company being so active in the community, so many years later (the initital release was in 2001). I…
That is some very well written documentation IMHO.
Re: HAProxy is not affected by the HTTP/2 Rapid Reset Attack
#25Earlier quoted context omitted.
Not by definition. Looking at Cloudflare's summary of the attack[0], part of it seems to rely on sending a request and then cancelling it in the very same packet. A trivial implementation might walk through the packet front-to-back, firing off requests and cancellations immediately as it encounters them. That would indeed still result in a lot of load on the servers behind the proxy. However, a reasonable alternative…
I thought you were going to suggest it to be processed like one of those trick exams of reading all of the questions before answering any of the questions where the last question is something so obvious that like stand up sit down, then turn in the test with out writing anything on it. So in this case, read all of the instructions in the packet. If the last is CANCEL, do nothing.
Re: HAProxy is not affected by the HTTP/2 Rapid Reset Attack
#26I'm quite impressed with HAProxy. It takes a little effort to fully understand the configuration file format (hint: you've got to read the documentation, not just look at examples to fully grok it), but it's so worth it, IMO. It's also a nice treat to have the founder and technical leader (Willy Tarreau) of the HAProxy company being so active in the community, so many years later (the initital release was in 2001). I…
Agreed. Haproxy is an absolute wonder compared to similar systems. It all just feels so much cleaner, thought out, and built from the ground up for many different use cases. It very much has a feel that reminds me a lot of the spirit of sqlite.
Re: HAProxy is not affected by the HTTP/2 Rapid Reset Attack
#27Earlier quoted context omitted.
Agreed. Haproxy is an absolute wonder compared to similar systems. It all just feels so much cleaner, thought out, and built from the ground up for many different use cases. It very much has a feel that reminds me a lot of the spirit of sqlite.
How does it compare with Caddy?
HA Proxy is robust, comprehensive, mature, and bulletproof. It's basically boring because it works so well.
If you have to choose only one to learn, choose HA Proxy.
Re: HAProxy is not affected by the HTTP/2 Rapid Reset Attack
#28Re: HAProxy is not affected by the HTTP/2 Rapid Reset Attack
#29Earlier quoted context omitted.
How does it compare with Caddy?
Caddy is a bit quick and dirty, rapidly-developing, with neat plugins but hard to configure for more complex scenarios and too light on the docs (IMO). HA Proxy is robust, comprehensive, mature, and bulletproof. It's basically boring because it works so well. If you have to choose only one to learn, choose HA Proxy.
Re: HAProxy is not affected by the HTTP/2 Rapid Reset Attack
#30I'm quite impressed with HAProxy. It takes a little effort to fully understand the configuration file format (hint: you've got to read the documentation, not just look at examples to fully grok it), but it's so worth it, IMO. It's also a nice treat to have the founder and technical leader (Willy Tarreau) of the HAProxy company being so active in the community, so many years later (the initital release was in 2001). I…
Agreed. Haproxy is an absolute wonder compared to similar systems. It all just feels so much cleaner, thought out, and built from the ground up for many different use cases. It very much has a feel that reminds me a lot of the spirit of sqlite.