Re: HTTP/1.1 Request Smuggling Defense using Cryptographic Message Binding (new draft)

On Wed, Oct 22, 2025 at 02:22:06PM -0400, Erik Nygren wrote:
> Oh, excellent point.  I guess that's a reason why we do need the
> negotiation at the TLS layer to ensure the next hop knows the protocol and
> can strip them out.

There is a way in HTTP to do global options, which is hop-by-hop (unless
the intermediary for some reason is a global forwarder that does parse
HTTP). However, at least some servers do not handle those, and there
might be too many servers that are outright allergic to such requests.




-Ilari

Received on Thursday, 23 October 2025 14:03:36 UTC