HTTP/1.1 must die: the desync endgame
Upstream HTTP/1.1 is inherently insecure and regularly exposes millions of websites to hostile takeover. Six years of attempted mitigations have hidden the issue, but failed to fix it.
🌐 https://portswigger.net/research/http1-must-die
#web #internet #http #http2 #website #endgame #desync #http1 #http1x #h2 #insecurite #webdev
