Readit News logoReadit News
AceSlash commented on HTTP/3: Everything you need to know about the next-generation web protocol   portswigger.net/daily-swi... · Posted by u/homarp
jiggawatts · 4 years ago
That’s because HTTP/2 broke every capability that was not used by Google.

NTLM auth… broken.

Client cert auth (mTLS)… broken.

Etc…

Monopolies are dangerous because they can accidentally lock out their competition without even trying.

They just have to focus on their own problems and ignore other people’s problems… because they can.

AceSlash · 4 years ago
Indeed, I was surprised when we tried to move a B2B application using mtls to http2 and realised that it simply was not implemented!

I know that's not used a lot but it is still used sometime when accessing critical systems.

I suppose that in the long run, mtls will completely disappear because of that, strange for a protocol that advertise itself as more secure to remove this option.

u/AceSlash

KarmaCake day101December 15, 2020View Original