v1 of HTTP Integrity Demos is up at lucaspardue.com/integrity-de.... Browser-based interactive demos to help understand RFC 9530 headers like Content-Digest, Repr-Digest and more
Lucas Pardue
@simmervig.org
Protocol nerd at Cloudflare. QUIC WG co-chair. Thoughts belong to me.
QUIC connections can negotiate an idle timeout once during the handshake, and never change it. Perhaps it would make sense to make it mutable? I'm not sure! My slides from IETF 126 github.com/quicwg/wg-ma...
Forget coding, I've been vibe tabbing. Started learning bass and use songsterrs AI tool. Not perfect but has taught me more about moving around the fretboard than I imagined. For example, Rosa Walton's "halfway round the world" www.youtube.com/watch?v=OGbV... www.songsterr.com/a/wsa/rosa-w...
Halfway Round The World Bass Tab by Rosa Walton | Songsterr Tabs with Rhythm
Halfway Round The World Bass Tab by Rosa Walton. Free online tab player. One accurate version. Play along with original audio
songsterr.com
Starting in a couple on minutes!
📢 We're just about 1hr away. ✨ SPDY STREAM 036 ✨ will be about RFC 9114. More colloquially know has HTTP/3 or H3 for short. If you have q?s, join us. @simmervig.org will ready and willing. All details in the pinned post!
For the 2nd time in a month, I'm welcoming an authority on protocols: @simmervig.org , QUIC and WebTransport @quicwg co-chair will join me to chat all things HTTP3, and how it speeds up all these apps you're building + shipping 📆 Friday June 12th ⏰ 1pm EST, 6pm 🇬🇧 🔗 www.youtube.com/live/TXPz94_...
I looked through Common Crawl and found over 300,000 parseable RSS/Atom feeds, confirming that Web feeds are still a major part of the Open Web. But most aren’t high quality, and autodiscovery often points users at stale or abandoned feeds. https://mnot.net/blog/2026/feed-survey
Renewed my @fastmail.com subscription after 2 years of it just working and no other bullshit. Feels good to pay for stuff like this.
Forty years ago, 21 people gathered for the first meeting of what became the IETF. Today, nearly 8000 IETF participants from around the world collaborate in more than 100 working groups and every day billions of people use technologies developed in the IETF. https://www.ietf.org/blog/ietf-40/
I'm watching Angel as a mindless guilty pleasure. In S2 E9, they seem to have forgotten to green screen the demon's lower half after it got chopped off. Not sure if this is due to 16:9 aspect or if the booboo was aired
HTTP/2-based DoS attacks are here to stay. Many implementations are hardened to them. Quirky behaviour can trigger defenses and cause ENHANCE_YOUR_CALM. Read one of my latest trips down a debugging rabbit hole. blog.cloudflare.com/go-and-enhan...
Go and enhance your calm- demolishing an HTTP:2 interop problem
HTTP/2 implementations often respond to suspected attacks by closing the connection with an ENHANCE_YOUR_CALM error code. Learn how a common pattern of using Go's HTTP/2 client can lead to unintended ...
blog.cloudflare.com
Glad to announce that my team at @cloudflare.social released a 1.0.0 version of a cross-browser web performance testing agent that supports Chrome, Firefox, Safari and Edge. Thank you to @tkadlec.bsky.social for making it happen and writing most of the code so far! github.com/cloudflare/t...
GitHub - cloudflare/telescope: Cross-browser web performance testing agent
Cross-browser web performance testing agent. Contribute to cloudflare/telescope development by creating an account on GitHub.
github.com
About 6 months ago Louis Navarre reached out to report some DoS-related vulnerabilities in quiche's ack processing. We fixed it up and saw no evidence that the vulnerabilities had been exploited. Check out the deep dive blog post: blog.cloudflare.com/defending-qu...
Defending QUIC from acknowledgement-based DDoS attacks
We identified and patched two DDoS vulnerabilities in our QUIC implementation related to packet acknowledgements. Cloudflare customers were not affected. We examine the
blog.cloudflare.com
Some news.. blog.cloudflare.com/moq/
MoQ: Refactoring the Internet's real-time media stack
For years, developers have been stitching together multiple protocols for real-time media, trading latency for scale and simplicity. Media over QUIC (MoQ) is a new IETF standard that resolves this con...
blog.cloudflare.com
Watching Usyk vs. Dubois squashed into a sports bar booth in Porto with 4 randoms, 2 from London, 2 from Ukraine, was not on the bingo card. But it all worked out.
I can predict how these new age checks are going to go using two pictures
I've heard of crackpot science. I guess the future equivalent is grokbot science
"I’ll go down this thread with GPT or Grok and I’ll start to get to the edge of what’s known in quantum physics and then I’m doing the equivalent of vibe coding, except it’s vibe physics,” said Travis Kalanick, the founder of Uber. gizmodo.com/billionaires...
I'm excited to announce I'll be at gRPC Conf on August 26 2025 to present how Cloudflare built its gRPC support first launched in 2020, and how we've been adding gRPC over HTTP/3 support lately. Session details at: grpcconf2025.sched.com/event/26BMY/...
gRPC Conf 2025: Bringing HTTP/3 To gRPC at Cloudflare Sc...
View more about this event at gRPC Conf 2025
grpcconf2025.sched.com
Hot off the press, happy to announce the adoption and publication of datatracker.ietf.org/doc/html/dra... Unencoded Digest is one of the missing pieces for certain use cases like the W3C signature-based integrity work. Helping to cover cases where encoding and transform independence are paramount
HTTP Unencoded Digest
The Repr-Digest and Content-Digest integrity fields are subject to HTTP content coding considerations. There are some use cases that benefit from the unambiguous exchange of integrity digests of unenc...
datatracker.ietf.org
An IRTF Retrospective – in which I reflect upon my time as Chair of the IRTF csperkins.org/standards/20...
Colin Perkins : Standards News : An IRTF Retrospective
csperkins.org
Wouldn't call it vibe coding but I've been using some AI to add features to throwaway test toys written in Go to Get Shit Done. Look out for some future updates about the $thing these toys are helping to make robust.
Using Internet standards to improve the the way automed traffic / bots can interact with the world. Namely two methods: HTTP Signatures (RFC 9421) and req mTLS flag (draft-jhoyla-req-mtls-flag) blog.cloudflare.com/web-bot-auth/
Forget IPs: using cryptography to verify bot and agent traffic
Bots now browse like humans. We're proposing bots use cryptographic signatures so that website owners can verify their identity. Explanations and demonstration code can be found within the post.
blog.cloudflare.com
AI slop has gotta stop. Hysterical* thing with this bullshit report to curl's hackerone (hackerone.com/reports/3125...) "HTTP/3 Stream Dependency Cycle Exploit" is we took great pains to standardize a priortization scheme that entirely did away with stream dependencies. * not the jovial definition
Unsupported Browser | HackerOne
hackerone.com
My team at Cloudflare are hiring mid-level and senior engineers to help us go deep on network protocols (HTTP, QUIC, TLS etc.) as we build and deploy our new Rust-based proxy. More details (including location) over on LinkedIn: www.linkedin.com/posts/lucasp...
The Cloudflare Protocols team is hiring for a number of roles! Come work… | Lucas Pardue
The Cloudflare Protocols team is hiring for a number of roles! Come work with me and my awesome manager Michelle Torres 🏳️🌈. We're looking for experienced mid-level and senior engineers to go d...
linkedin.com
Multipath Extension for QUIC is now in Working Group Last Call. datatracker.ietf.org/doc/draft-ie...