by 120bits on 10/12/23, 7:04 PM with 62 comments
by sickofparadox on 10/12/23, 8:12 PM
by dang on 10/12/23, 7:52 PM
HAProxy is not affected by the HTTP/2 Rapid Reset Attack - https://news.ycombinator.com/item?id=37837043 - Oct 2023 (31 comments)
The largest DDoS attack to date, peaking above 398M rps - https://news.ycombinator.com/item?id=37831062 - Oct 2023 (461 comments)
HTTP/2 Rapid Reset: deconstructing the record-breaking attack - https://news.ycombinator.com/item?id=37831004 - Oct 2023 (22 comments)
HTTP/2 zero-day vulnerability results in record-breaking DDoS attacks - https://news.ycombinator.com/item?id=37830998 - Oct 2023 (69 comments)
The novel HTTP/2 'Rapid Reset' DDoS attack - https://news.ycombinator.com/item?id=37830987 - Oct 2023 (103 comments)
by ComputerGuru on 10/12/23, 11:20 PM
by nimbius on 10/12/23, 11:38 PM
Curious to see f5 still playing games with their own cve disclosure on the bigip product though...assigning it a mitre cw400 is just lying.
by eastdakota on 10/12/23, 8:39 PM
by codetrotter on 10/12/23, 8:02 PM
I didn’t find anything relevant so I assumed that Nginx was not affected.
Turns out that was not a good assumption :p
by amelius on 10/13/23, 6:45 AM
Title should contain this info.
by getcrunk on 10/13/23, 12:45 AM
What do you guys use? Anything foss and not an applicance?
by 1vuio0pswjnm7 on 10/12/23, 11:53 PM
According to HTTP/2 proponents, the protocol originated at an online advertising services company and was developed by companies that profit from sale and delivery of online advertising, HTTP/2 was designed to "speed up the web".
I respect that opinions on HTTP/2 may differ. If someone loves HTTP/2, then I respect that opinion. In return I ask that others respect opinions that may differ from their own, including mine. NB. This comment speaks only for the web user submitting it. It does not speak for other web users. IMHO, no HN commenter can speak for other web users either. Thank you.
by blackbeans on 10/14/23, 4:49 PM
by phendrenad2 on 10/12/23, 8:58 PM
by andrewstuart on 10/12/23, 10:43 PM
by bullen on 10/13/23, 8:16 AM
Nothing Google or Microsoft does will dethrone it.
Forget the browser; use a C or Java client and HTTP.
If they block port 80, just use another port.
They cannot win.
by ChrisArchitect on 10/12/23, 8:36 PM
Lots of discussion and submissions related to this over the last few days, not to mention this submitted 2 days ago