frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

HTTP/1.1 Must Die – The Desync Endgame Begins

https://http1mustdie.com/
8•pabs3•4h ago

Comments

superkuh•3h ago
HTTP/1.1 is inherentely more resistant to centralized political and social pressure than HTTP/2 and HTTP/3 as those have baked in (to 99.9999% of user agents and libs) requirements for CA TLS. It's also far more robust over long time periods.

I understand that for business and institutional use cases HTTP/1.1 is undesirable. But for human use cases, like long lasting and robust websites that don't just become unvisitable every ~3 years (with CA cert expirations, etc, etc) HTTP+HTTPS on HTTP/1.1 is irreplacable.

Browsers, lib devs, and web developers, should consider the needs of human persons and not just corporate persons. This is a misguided declaration at best and one who's context needs to be clearly defined.

altairprime•3h ago
Desync attacks do not affect static and public content, which is the only form of “long lasting and robust websites” available; so it is perfectly reasonable to continue serving such content over HTTP with nothing to fear from desyncs.
tptacek•3h ago
This is James Kettle, who more or less invented HTTP/1.1 desync attacks, and has delivered several years of Black Hat talks about them; he's basically the unofficial appsec keynote at Black Hat.
oidar•1h ago
Isn't this just an announcement? I thought HN didn't allow "announcement" posts.

Replit Agent deleted a $1M SaaS startup's production DB

2•Arindam1729•4m ago•2 comments

I´m migrating a webpage that uses Zend Framework 1. Do you have some advice?

1•sfebreiro•4m ago•0 comments

DailyMe: Write less. Do more. Feel better

https://apps.apple.com/us/app/dailyme-journal-your-ai-diary/id6745645320
1•gerardozaguirre•6m ago•2 comments

Capstone–modular platform for self-development, mastery tracking and AI coaching

https://www.theevolved.net
1•Poakess•8m ago•1 comments

Why Some Satellites Use NetBSD?

https://machaddr.substack.com/p/why-some-satellites-use-netbsd
1•Bogdanp•9m ago•0 comments

How to handle people dismissing io_uring as insecure?

https://github.com/axboe/liburing/discussions/1047
6•nromiun•10m ago•0 comments

SubTropolis and KC's Limestone Caves

https://kcyesterday.com/articles/subtropolis
1•taubek•14m ago•0 comments

Show HN: A simpler/cheaper alternative to Canny with a better free tier

https://www.userband.com/
1•ashbrother•15m ago•0 comments

Updating Your Brain's Software

http://happinessbeyondthought.blogspot.com/2018/03/updating-your-brains-software.html
1•andsoitis•18m ago•0 comments

Alaska Airlines grounds fleet nationwide

https://www.seattletimes.com/business/alaska-airlines-grounds-nationwide-fleet/
1•sugarpimpdorsey•19m ago•0 comments

Weak password allowed hackers to sink a 158-year-old company

https://www.bbc.co.uk/news/articles/cx2gx28815wo
1•mmarian•19m ago•0 comments

Build an Enterprise-Ready AI Powered Applicant Tracking System [video]

https://www.youtube.com/watch?v=iYOz165wGkQ
1•ent101•21m ago•0 comments

Knowledge Pillars and Certiport Global Partnership Announcement

https://knowledge-pillars.com/knowledge-pillars-and-certiport-global-partnership-announcement/
1•taubek•30m ago•0 comments

Show HN: I built a tool that generates Brat-style covers

https://bratgenerator.icu
1•kristoff200512•35m ago•0 comments

Ask HN: Advice on Offer

1•thathnwisdom•39m ago•1 comments

Perseids Meteor Shower Could Feature 50 to 100 Meteors per Hour

https://www.discovermagazine.com/the-sciences/the-2025-perseids-meteor-shower-could-feature-50-to-100-meteors-per-hour-and
1•danboarder•40m ago•0 comments

Rsyslog Goes AI

https://www.rsyslog.com/rsyslog-goes-ai-first-a-new-chapter-begins/
2•Deeg9rie9usi•41m ago•0 comments

Lightning Network has Failed [video]

https://www.youtube.com/watch?v=5Cq0C0SpbkY
1•richardanaya•43m ago•0 comments

Bright idea paves way for longer-lasting deep blue LEDs

https://cosmosmagazine.com/technology/materials/better-deep-blue-leds/
1•Bluestein•45m ago•0 comments

Microsoft releases emergency patches for SharePoint RCE flaw exploited in attack

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-emergency-patches-for-sharepoint-rce-flaws-exploited-in-attacks/
2•DocFeind•46m ago•0 comments

Microsoft Response Point PBX System [video]

https://www.youtube.com/watch?v=nCPpkY1TD9Q
1•lurtbancaster•50m ago•0 comments

Dissecting the NVIDIA Blackwell Architecture with Microbenchmarks

https://arxiv.org/abs/2507.10789
1•matt_d•52m ago•0 comments

Delta Pilot Debriefs Cabin After Near Mid Air Collision with B52 Bomber

https://old.reddit.com/r/aviation/comments/1m49kz1/delta_pilot_debriefs_cabin_after_near_mid_air/
3•Onavo•54m ago•0 comments

SIMD Perlin Noise: Beating the Compiler with SSE

https://scallywag.software/vim/blog/simd-perlin-noise-i
2•homarp•57m ago•0 comments

Where can I sell a dataset I've created?

3•tflinton•59m ago•3 comments

Community Publishing Platform

https://hackernoon.tech/
1•smooke•1h ago•0 comments

ToolShell Mass Exploitation (CVE-2025-53770)

https://research.eye.security/sharepoint-under-siege/
2•panarky•1h ago•0 comments

Claude Code Helped Me Understand a Legacy Codebase in One Day

1•IgorGanapolsky•1h ago•0 comments

Show HN: The Next Modern Test By pytest-modern

https://github.com/zen-xu/pytest-modern
3•zen-xu•1h ago•1 comments

October 22, 2025 is +++ Day!

https://www.southernamis.com/group/day/discussion
3•JPolka•1h ago•0 comments