RE: #612: 9.2.2 and ALPN

>I assume that there is an implied:

>BAD = peer MAY fallback to h1 (if able to influence ALPN protocol selection)

>and that will not be seen as a downgrade attack (or at least and acceptable one).

So long as  some servers treat HTTP/1.1 and HTTP/2.0 as interchangeable, retrying requests as HTTP/1.1 could constitute a downgrade attack


In other news, on the hopeful side, Microsoft just back-ported TLS 1.2  GCM ciphers to more OS platforms while fixing a  SChannel bug



Greg Wilkins <>  @  Webtide - an Intalio subsidiary HTTP, SPDY, Websocket server and client that scales  advice and support for jetty and cometd.

Received on Wednesday, 12 November 2014 13:39:51 UTC