Comparing HTTP/3 vs. HTTP/2 Performance (2020)
blog.cloudflare.com
blog.cloudflare.com
443 milliseconds!! When typical user latency is sub 50 milliseconds, requiring 443 milliseconds to get a lightweight page displayed on the screen is terrible.
Users perceive 100 milliseconds as near-instant, and that ought to be the target. With 50 milliseconds of network latency, and 0-rtt support, that gives 50 milliseconds for server and client processing+rendering. Ought to be very do-able.
The fact it has not been done really is a failure of software engineering as an industry - we always favour more layers of abstraction over perfecting the user experience.
You're forgetting DNS lookup latency (could be several sequential lookups), and potential protocol switch from HTTP to HTTPS. Having 0-rtt support doesn't do you any good if you don't know which server to send to.
It is one that could be fixed by developers if only the correct flags were set during compilation of the HTTP/3 libs and during their linking to the relevant browsers. But no one seems to care about human use cases. It's corporate security uber alles.
Why? And why https with http 1.1 not?
This is nonsense: if you set up Let’s Encrypt or the equivalent, which is increasingly built in, it’ll keep working for HTTP 1-3. If you don’t, you need to rotate certificates for all of them.
If your claim is that the HTTP 1 option is better because you can be insecure after the certificate expires, that’s conflating two separate things and saying that you don’t care about your users privacy and security, which might be true but is a more compelling argument against using that service than against HTTP/2.
Like said, HTTP+HTTPS in HTTP/3 would be perfect. Everyone could be happy and websites could have infinite unmaintained lifetimes and anyone could visit without getting approval from a third party corporation every 3 months. But nope, the big tech companies, and even Mozilla, refuse to implement an HTTP/3 that supports HTTP+HTTPS. It's flabberghasting, unless you view it through the lens of the needs of commerce only. That is my point.
*re: This is nonsense: So when I set up lets encrypt using an acme (1) client it should still work today? Oh wait, they dropped acme 1 support entirely and only support acme 2 now (and will again with acme 3). And that's ignoring that whatever acme client you pick is going to have breaking changes too over time (even if it's acme.sh!). Then there's the 2018 LE root cert expiration... then the 2024 one, then there's TLS version sun-setting...). It is not so non-sensical down in the weeds of actually hosting a 90-day cert CA TLS website over more than a few years. And just to note: I love LE. I use LE for some websites. I think it's great. I love HTTPS too. I just think HTTPS-only instead of HTTP+HTTPS is very damaging socially.
Running a webserver is as simple as "apt install nginx", forwarding ports 80/443 on your router and saving a index.html to the webroot directory. HTML and files in directories live forever. And there's no need for a domain, DNS, or especially an "application". Just drag and drop myphoto.jpg to ~/www/ in your GUI file manager and you're ready to send the link, http://my.ip.is.here/myphoto.jpg to friends. And it'll last forever with no security worries. nginx remote exploits are once a decade, if that. Sure you might have to re-link if your IP changes but that's not a problem. Sure you site will be inaccessible sometimes if your computer is off, but you're not sharing files to friends during that time so it's fine. The requirements of business use cases just don't apply. It's not "serious".
Seriously, this is just embarrassing. If it’s too hard for you to add a couple lines of config to enable Let’s Encrypt (apt will get you Apache w/mod_md or Caddy, too), it’s also too hard to run the rest of the server - and neither are that hard.
The amount of times certificates have run out breaking things is astounding.
So I work around all certificate test the first thing I do when integrating with an external HTTPS site.
Good job people that get paid by HTTPS.
The performance of these binary protocols does not scale on most server implementations.
The protocol is not the bottleneck, the parallelism and memory latency is.