https://dropbox.tech/frontend/investigating-the-impact-of-ht...
(Discussed at https://news.ycombinator.com/item?id=36027702.)
For the majority of our global users, HTTP3 reduced network latencies by 5-15ms (or 5%). While this is an improvement, these wins would appear negligible to the average user. At p90, however, HTTP3 demonstrated massive improvements, with a latency reduction of 48ms (or 13%)—and at p95, a reduction of 146ms (21%). This could be explained by the fact that HTTP3 is better at handling packet drops in parallel connections by eliminating head-of-line blocking; because packet drops are more likely to occur in networks with suboptimal connection quality, the benefits of HTTP3 are more visible at the higher percentiles.Of course it's true that QUIC is a complexity monster. OTOH HTTP/3 is actually quite simple when you have the QUIC layer implemented. A simple HTTP/3 server is no more than this:
https://github.com/aiortc/aioquic/blob/main/examples/http3_s...
People have definitely gotten more impatient over the years.
There was quite a bit of pushback on this in the IETF from financial institutions that think they have mandatory obligations to spy on their employees.
Here is a relevant HN discussion thread from 2016 about TLS 1.3, most of which applies to HTTP/3: https://news.ycombinator.com/item?id=12641880
To be fair, they do have mandatory requirements to prevent their employees from doing some things online in some cases. For example - some of the rules around coordination on a trading floor: https://www.sec.gov/rules/sro/nyse/2017/34-80374-ex5.pdf
Or - in many cases they are legally required to retain a copy of communications sent, and there are a large number of sites that offer diverse services banks want that also happen to have "chat/email" hidden as a feature. That's legally communication, and they often can't collect and retain it.
Long story short - they don't really care so much, because many of them are already doing this collection now in other ways... my first job out of college 13 years ago was helping large banks transition this monitoring and policy enforcement to browser extensions (Guess who was grumbling about the MV3 changes in chrome, for very similar reasons).
Now they're moving to directly adding the monitoring in the OS/Kernel
Does this mean financial software has root-kits build in? Good to know!
So this means every banking computer is fundamentally compromised at the OS level. Let' see how long it takes until this backfires. Could be a nice global firework when it goes off.
Who exactly builds those root-kits? How good are they protected against supply chain attacks?
I assume Google and co. will fix this if it ever starts to seriously benefit platforms like KiwiFarms, which in the last year was being blocked by CenturyLink, a major US ISP. I also predict these QUICfixes will be met with broad enthusiasm by HNers.
plus, in real-world use cases it's probably a perf loss running TLS like this fwiw.
Are there any prove points for this claim besides this shout-out?
QUIC is more like a modern TCP. What you do with such a protocol is unrelated to the protocol as such. You can open secure connections and stream data with it. That's all. Everything else is on the application side.
> Something like dns-over-http/3 is, allegedly, referred to internally at Google as the anti-Pi-hole
This claim sounds like anti QUIC FUD.
Nothing can stop you from using a Pi-hole like device as your primary DNS resolver!
(OK, I admit Google could try to hard-code their DNS servers in Chrome. But I'm very unsure they would make it through the following shit storm in one piece.)
It dates back to a more draconic era of firewall management, but has also worked its way into DHCP (https://en.wikipedia.org/wiki/Web_Proxy_Auto-Discovery_Proto...).
More relevantly, there's no reason they couldn't do the same before HTTP/3. Even with DNS traffic hijacking, they could just as well do DNS-over-TLS. Infiltrating advertising-related DNS is completely orthogonal to HTTP/3; agreed that the gp comment is FUD.
What? What is your source on this? How does the protocol stop you from using e.g. uBlock to filter the domains at the application level?