Re: Prague side meeting: HTTP/2 concurrency and request cancellation (CVE-2023-44487)

Stefan Eissing writes:

> > Does any published data exist on how "100" relates to how many streams
> > real-life legit clients /actually/ open on a new H2 connection ?
> See >
> They tried to lower it and found a page where browsers do open 100 
> requests right away.

Yes, already saw that.

But 100 is not a hard limit, it is barely even guidance, so I wonder
what the actual, legit, in use in the wild, maximum is ?

100 ?  200 ?  1000 ?

It would be nice if we had some actual statistics to guide us, rather
than justing picking 100 out of the blue ?

Received on Friday, 13 October 2023 11:34:42 UTC