Sure there are good things about it, and many great enhancements, but the larger mechanic of the protocol (the most important part really) has been significantly worsened. I'd rate them as follows:
HTTP3 > HTTP1.1 > HTTP2
QUIC is an amazing protocol, I have no complaints about it, and I'm very happy they decided to go with it for HTTP3. However the decision to make HTTP2 traffic go all through a single TCP socket is horrible, and makes the protocol very brittle under even the slightest network decay or packet loss. Any level of head-of-line blocking severely degrades the entire stream, even for unrelated requests.
Sure it CAN work better than HTTP1.1 under ideal network conditions, but any network degradation is severely amplified, to a point where even for traffic within a datacenter can amplify network distruption and cause an outage.
HTTP3 however is a refinement on those ideas, and gets pretty much everything right afaik.
I'm predicting that eventually Google will start deranking HTTP 1.1 websites.
You do not see how lack of built-in authentication increases complexity of implementing your own website as opposed to "outsourcing" stuff to Gmail, Google Docs and so on? You don't see the zillion "sign in with Google" buttons all over the web? You don't see how cookies are abused for tracking, which benefits Google orders of magnitude more than it would a smaller company?
It's in no way easier than adding keycloak authentication for example, which is another (selfhosted) external authentication solution.
Social auth isnt there to make authentication easier for the website owner. He still has to do everything he'd have to do if he didn't use it.
It's there for the users, do they don't need to remember a bazillion passwords
Google, a multi-billion dollar corporation that owns most of the browser and search market share, a company that dictates the next transport-layer protocol we will use - this company struggles to design a session-handling mechanism that would out-compete an ugly hack that Netscape ductaped to HTTP in mid-90s.
[1] https://varnish-cache.org/docs/trunk/phk/http20.html#beating...
Cookies were a hack to add sessions on top of http.
[1] https://varnish-cache.org/docs/trunk/phk/http20.html#beating...
HTTP1/2 = TCP, which has dedicated hardware to offload major parts of the protocol overhead.
QUIC = UDP, but re-implements some features of TCP in software, leaving the CPU to handle things it didn't have to before.
I plan on purchasing the book as reviewed by this blog post: https://petewarden.com/2015/10/08/smartphone-energy-consumpt...
Wasn't Google already publishing and promoting QUIC before SPDY got adopted as the basis for HTTP/2? SPDY was more conservative because it didn't replace TCP, QUIC wasn't a fix for SPDY being broken, it was a concurrent and less conservative effort poo.