Live data from Hacker News

HTTP/2 rapid reset attack impacting Nginx products

nginx.com

61–66 of 66 posts

Re: HTTP/2 rapid reset attack impacting Nginx products

#61
post #60
post #58

Earlier quoted context omitted.

> They are those that disable HTTP. Who's disabling HTTP? > Like it was not enough to make HTTPS default, they need to eradicate the opposition. I think you need to elaborate your world view by many paragraphs before I can understand what you're trying to say. You're against HTTPS? Plain TLS wrapping HTTP? > they profit from root certificates. The (web) root certificate industry has never been weaker than it is today…

All major browsers have now removed HTTP available as default = you need to change a setting to even be able to access a HTTP url. Anti-virus software blocks native apps that try to connect on port 80 and you cannot make them open the port even if the setting is available. I will always use HTTP/1.1 on port 80 but my customers wont be able to connect even if they try, my only option is to tell them to uninstall their…

> you need to change a setting to even be able to access a HTTP url.

No. http://captive.apple.com seems to load just fine for me.

> I will always use HTTP/1.1 on port 80 but my customers wont be able to connect even if they try, my only option is to tell them to uninstall their anti-virus and hope that works.

Because of infrastructure malware like ad injectors at ISPs, it's probably in your customers best interests to use HTTPS.

Hell, it's better to use HTTPS with a self signed cert than HTTP.

> hurts a producer that is not complying with the authority.

There's always the risk of a conspiracy of vendors deplatforming someone. That's true. I'd be more worried about your ISPs or electricity companies unilaterally shutting off your service.

If you see Letsencrypt going all political, like Patreon, and kicking off people with the wrong views, then yeah we have a problem.

> They will say that to use unencrypted protocols you need a license from your government.

Haha, the wind is blowing the other way, buddy.

Re: HTTP/2 rapid reset attack impacting Nginx products

#62
post #61
post #60

Earlier quoted context omitted.

All major browsers have now removed HTTP available as default = you need to change a setting to even be able to access a HTTP url. Anti-virus software blocks native apps that try to connect on port 80 and you cannot make them open the port even if the setting is available. I will always use HTTP/1.1 on port 80 but my customers wont be able to connect even if they try, my only option is to tell them to uninstall their…

> you need to change a setting to even be able to access a HTTP url. No. http://captive.apple.com seems to load just fine for me. > I will always use HTTP/1.1 on port 80 but my customers wont be able to connect even if they try, my only option is to tell them to uninstall their anti-virus and hope that works. Because of infrastructure malware like ad injectors at ISPs, it's probably in your customers best interests t…

It loads fine because you enabled it.

Re: HTTP/2 rapid reset attack impacting Nginx products

#63
post #62
post #61

Earlier quoted context omitted.

> you need to change a setting to even be able to access a HTTP url. No. http://captive.apple.com seems to load just fine for me. > I will always use HTTP/1.1 on port 80 but my customers wont be able to connect even if they try, my only option is to tell them to uninstall their anti-virus and hope that works. Because of infrastructure malware like ad injectors at ISPs, it's probably in your customers best interests t…

It loads fine because you enabled it.

Default chrome. I'm not even aware of the option you mention.
Post reply on HN