Cloud giants sound alarm on record-breaking DDoS attacks
cybersecuritydive.com
cybersecuritydive.com
Sure, HTTP 1.1 makes it extremely awkward to have lots of backend requests in flight per front end connection. But HTTP 2.0 makes a factor of 100 variation in the backend / frontend ratio trivial, and that’s a big number already.
Calling this critical vulnerability in the protocol seems like an odd way to phrase what I see as an accounting failure in the overall system that apparently affected everyone. If I were implementing such a system, I wouldn’t have wanted to ignore the difference between an HTTP 1.0/1.1 connection with a single backend request and a 2.0 connection with 100, and catching the case where a 2.0 connection had 100 live backend requests and a couple thousand more orphaned requests seems like a natural result of accounting the requests correctly in the first place.
https://blog.cloudflare.com/technical-breakdown-http2-rapid-...