HTTP/2
15
MENTIONS
10
EPISODES
10
PODCASTS
Search complete. 15 mentions across 10 episodes found for "HTTP/2".
Sep 8, 2026
Mike Belshe: The 100 Bitcoin Hacking Bounty & How to Hold Bitcoin Where the ETFs Do
M
47:22Mike BelsheGUEST
It's taking ideas at the transport level, at the application level of how to make a faster protocol.
M
47:29Mike BelsheGUEST
I did that, put that into a thing we called Speedy, and then that's now known as HTTP2 today.
M
47:35Mike BelsheGUEST
So I'm the lead author on that.
M
47:37Mike BelsheGUEST
I was very lucky to have some other people at Google that were excited to make that work.
ULS 269: Kerfluffel - CERN, Ur, and AGENTS
J
79:11Jeff MassieHOST
There's a speed change, which is something called Happy Eyeballs version three that should make browsing go a little quicker.
J
79:19Jeff MassieHOST
Simply, every time Firefox loads a page, it has to pick a path to reach a server, maybe over IPv4, IPv6, maybe HTTP2 or the newer HTTP3.
J
79:30Jeff MassieHOST
The older Firefox versions picked one path and waited to see how it worked before trying another.
J
79:35Jeff MassieHOST
If that first go was slow or broken, the page just sat there.
Go releases and events from EMEA and around the world
J
24:45Jonathan HallHOST
I suppose it provides some security implications as well because you can hide a payload inside of the body that doesn't show up in in proxy logs or whatever.
J
24:56Jonathan HallHOST
I would say this is the first big change to HTTP other than HTTP2 or HTTP3.
J
25:03Jonathan HallHOST
But as far as like this sort of vanilla HTTP, this is the biggest change in quite a long time.
J
25:07Jonathan HallHOST
It's not a architecturally...
September 4th 2026 - Google Cloud Update
S
9:59speaker_0HOST
Plus, GKE Gateway now supports strong cookie affinity for session stickiness in GA. GKE has also changed the priority of some default firewall rules for services from 1,000 to 999, so check your custom rules to make sure nothing gets unexpectedly blocked.
S
10:16speaker_0HOST
On the service mesh front, Managed Cloud Service Mesh is rolling out a new proxy version that maps closely to Envoy version 137, which resolves HTTP.2 security vulnerabilities.
S
10:28speaker_0HOST
Also, Cloud Service Mesh version 1.30.4 ASM.1 is now available for in-cluster deployment, while in-cluster version 1.27 is officially no longer supported.
S
10:40speaker_0HOST
In networking, you can now create Compute Engine instances with multiple virtual network interfaces, or VNICs, within the same VPC network.
What is Cross-Origin Storage? - Thomas Steiner
C
31:34Christian HeilmannHOST
excellent well thanks thomas this was once again an interesting thing i'm going to put an article around it as well once we have the recording here done and list to all the resources so people don't have to actually look at the banners that i put in there and uh yeah good luck with that i think it's a it's a great opportunity to think about uh differently and the sizes that we want to store these days.
C
31:55Christian HeilmannHOST
I mean, we kind of gave up on CDNs for things like jQuery because with HTTP2, it wasn't that much of an issue anymore, and people are not too worried about long...
C
32:07Christian HeilmannHOST
I mean, performance has changed a lot because people take on a lot more things.
C
32:12Christian HeilmannHOST
I mean, you can turn you can turn your app from a web app to an ai app just by renaming every loading into thinking and then making people wait that way and we kind of got got used to that one but it's a great opportunity to and i love that it's a that it's a what uh uh wicg uh thing as well and not just a google one so that there's more people involved as well and um yeah once again innovating in public and that's where people can take part in and we need you to actually tell us about what you think about that so take a look at the cross origin storage bits and bobs that thomas has talked about and i want to thank you for bringing it up to me so any last words for people out there
2.5 Admins 314: 50 PBS TBS
A
17:17Allan JudeHOST
Well, they get into a little more nuance.
A
17:19Allan JudeHOST
They have a- an example here of if there was a new HTTP 2 download service vulnerability.
A
17:24Allan JudeHOST
The classic way to solve that, which, oh, we'll just disable HTTP 2 and fall back to using old HTTP 1.1 until the system is patched.
A
17:31Allan JudeHOST
But that might have, you know, significant application and performance impact, right? It's gonna make everything too slow.
A
17:37Allan JudeHOST
So they're saying a more robust AI-driven network and workload-aware response system might be able to say limit how many concurrent streams each IP address can have.
2.5 Admins 314: 50 PBS TBS
A
17:17AlanHOST
Well, they get into a little more nuance.
A
17:19AlanHOST
I have an example here of if there was a new HTTP2 download service vulnerability, the classic way to solve that would be, oh, we'll just disable HTTP2 and fall back to using old HTTP1.1 until the system is patched.
A
17:31AlanHOST
But that might have significant application and performance impact, right? It's going to make everything too slow.
A
17:37AlanHOST
So they're saying a more robust AI-driven network and workload-aware response system might be able to say, limit how many concurrent streams each IP address can have.
Episode 331 - Being "Mythos" Ready, CRLF-Powered De-sync Attacks
S
70:36Seth LawHOST
A simple regex change, and all of a sudden, it's done.
S
70:41Seth LawHOST
But it does go back to this whole idea of, oh, it's HTTP 1.1 instead of HTTP 2.0.
S
70:47Seth LawHOST
I know they want HTTP 1.1 to go away, but let's be honest, it's never going to go completely away.
S
70:53Seth LawHOST
It's going to take a long time.
Mat Trudel on Building Bandit - the Web Server Running Your Phoenix App
M
37:16Matt TrudelGUEST
But it's essentially this realization that these AI-generated security vulnerabilities are coming in at a pace that is just, it's just too much to be able to, to be able to realistically absorb.
M
37:29Matt TrudelGUEST
I remember about a year and a half ago or so, there was a flurry of vulnerabili- of d- denial of service request, vulb, uh, vulner... denial of ser- denial of service attacks, excuse me, in the HTTP/2 world that, uh, when th- when these came out about a year and a half ago, they sounded at the time like it, like the, like, like the world was gonna end.
M
37:49Matt TrudelGUEST
You know, like, these were, these were incredibly, you know, like, uh, people couldn't believe how sophisticated these attacks were, and these were all human-reported.
M
37:57Matt TrudelGUEST
These were all human, you know, like, it was a hu- Like, they were, they were human researchers that found these, and they were, they were essentially the last, the last big human-sourced s- vulnerability crop was the, these ones around HTTP/2.
M
38:12Matt TrudelGUEST
And people thought the world was gonna end, and these ones that are coming in now from a lot of the AI agents are, like, 10 times deeper than this and 10 times more subtle, and, like, h- humans would never have found most of these.
M
38:25Matt TrudelGUEST
And they're completely valid.
9 MINS LATER
M
47:35Matt TrudelGUEST
But ultimately, those attacks don't look like a violation.
M
47:39Matt TrudelGUEST
They're not a thing that a general purpose pro- like HTTP focused test suite would find, right? They're, they're, the bugs are more shaped like almost using the best parts of the beam against itself in a number of cases.
Choosing the Right RPC Framework for .NET
A
4:47Artificial IntelligenceNARRATOR
It uses websockets when available and falls back to server-sent events or long polling, all over HTTP, TCP.
A
4:54Artificial IntelligenceNARRATOR
there is no native support for raw tcp sockets or named pipes signalr is expressly designed for client server communication over web-friendly protocols typically between browsers and servers grpc grpc uses http 2 as its transport with each call sent as an http to request a vera persistent connection typically tcp secured with tls On ASP.NET Core it supports standard TCP sockets by default and can be configured for Unix domain sockets or Windows named pipes in same machine scenarios.
A
5:29Artificial IntelligenceNARRATOR
Its IPC support has improved recently, but the framework fundamentally assumes a TCP, IP stack or an equivalent transport.
A
5:38Artificial IntelligenceNARRATOR
Core WCF Core WCF retains much of the multi-binding flexibility of Classic WCF, THOSM bindings are incomplete.
9 MINS LATER
A
14:26Artificial IntelligenceNARRATOR
The gap against MessagePack is what you would expect from a text encoding on a 10 MB binary payload.
A
14:32Artificial IntelligenceNARRATOR
SignalR is reasonably efficient for local IPC with binary encoding, but its HTTP-based communication cannot match the latencies of in-memory transports.
A
14:41Artificial IntelligenceNARRATOR
GRPC-GRPC was benchmarked in two local modes, HTTP 2 over TCP, one-way average of 26.
A
14:51Artificial IntelligenceNARRATOR
7 ms, two-way average of 63.8 ms.