HTTP/2.0 Opens Every New Connection It Makes With the Word 'PRISM' (jgc.org)
An anonymous reader writes: British programmer and writer John Graham-Cumming has spotted what appears to be a 'code-protest' in the next generation of the hypertext protocol. Each new connection forged by the HTTP/2.0 protocol spells out the word 'PRISM' obliquely, though the word itself is obscured to the casual observer by coded returns and line-breaks. Work on the hidden message in HTTP/2.0 seems to date back to nine days after the Snowden revelations broke, with the final commit completed by July of 2013. In July 2013 one of the protocol's architects appealed to the development group to reconsider design principles in the light of the revelations about the NSA's worldwide surveillance program.
HTTP/2.0 also supports the Bitcoin protocol which allows underpaid female STEM workers to drive 3D printed Uber cars or get a job (powered by DICE) delivering Arduinos via drones to Elon Musks new IoT manufacturing Chinese death factory.
If you remove the line feeds, you get PRI*HTTP/2.0SM.
for this to get "noticed"?
so much for open standards and open source software... 'its safe. you can look at the code yourself"... it took two and a half fucking years for someone to do just that.. and just to find an easter egg, not an embedded and obscured vulnerability.
One of our coders used a limerick, yes it was the man from Nantucket, as a static string. He used it to test some of the string utility functions he was developing. Forgot to remove it. Eventually a nosy customer found it by running strings on our executable and made a stink about it. (Never explained why they were poking around our executable with strings) It is out of our builds now, but if you do a blame on stingutils.cpp you can still see it and see how long it stayed in production.
sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
There haven't been tacos on Slashdot since Mr. Malda left four years ago.
Is this was slashdot has come to?
If that's true then, AFAIK, headers have always had some form of constant and, if not, there's consistent content in the individual packets that identify things like what stream they belong to.
"So long and thanks for all the fish."
and suddenly now we give a fuck?
Right, but not all headers can be encrypted. e.g. your letter still needs an unencrypted address or it can't be delivered.
its the same person posting like 8 times, he does this in everythread these days. i guess he likes talking to himself
have you seen my sig? there are many others like it but none that are the same
"Each new connection forged by the HTTP/2.0 protocol..."
So is that...
* forge (verb) 2. To form or create with concerted effort.
or
* forge (verb) 4. To create a forgery of; to make a counterfeit item of; to copy or imitate unlawfully.
?
https://en.wiktionary.org/wiki/forge
Dear Slashdot: next time you want to mess with the site, add a rich-text editor for comments.
microaggressive behavior
What, as in it'd take a million of them to cause even one real problem?
They needed a magic value to recognize HTTP/2.0 servers that would reliably fail on existing ones. As magic values are arbitrary, this one was good enough (i.e. actually fails on almost all servers), they simply picked something and moved on.
This is NOT something extra or unnecessary added to HTTP/2.0, it's just something arbitrary that they happened to pick as a "magic" value, not unlike those commonly found in most file formats.
Yes... all 30 seconds or so were wasted.
"Well kids, you tried your best, and you failed. The lesson is, never try." -Homer Simpson
Please be quiet - adults are trying to talk.
That's kind of what I was thinking - I wasn't sure that their comment was even salient but I'm not a crypto-geek and I knew that headers have pretty much always contained repeatable data and that it's not made a difference (AFAIK) so far. I probably should have phrased it better. I do know, by grace of having to learn a bunch, some basic networking but not a lot of crypto - enough to implement it if needed. I understand things like SYN and ACK, UDP, etc... I did not have the budget to hire a network admin (lots of years ago) and spent lots of time learning about it. I think the important thing I learned was to drop Cisco and go Juniper. *nods* But, I digress.
"So long and thanks for all the fish."
Does this apply only to forged connections or also to legit ones?
Real life is overrated.
Slander term used by people that think normal is somehow icky. (The variety of fuckups in the human race is both endless and astonishing....)
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
To anthropomorphize them because that's the way your brain works is a serious error.
It's called "colloquial language", and it appears to have got the point across to most other readers. But if you insist on discussing the process more formally in terms of "matching bits":
The PRI request method matches none of the methods in a pre-HTTP/2.0 server's list of acceptable methods. This causes the server to write a response that does not match the HTTP/2.0 upgrade pattern, even if the server's matching of the protocol version bits is incorrect. When the response fails to match at the client, the client switches to HTTP/1.1.
Are you sure Tepples supports you?
For those of us who are logged in, here is what your link points to:
APK agrees that hosts files are only one component in a layered security strategy [slashdot.org]. Eight years ago, he wrote a detailed article about the other layers [neowin.net].
--
Hosts file disadvantages: No wildcards, no NXDOMAIN, slow linear search, no per-user, no whole-LAN protection
I don't see him agreeing with you anywhere. He in fact strictly disagrees with you in part of that message. You really should use your account, it will change your world to see all those signatures you hate so much.
No complaints from me, I like APK's spam. Reminds me to use a host file. Also, his stuff is free.
Arg (don't feel like counting the a's, sorry) doesn't actually say he uses your software, just that he uses hosts files.
And that KGIII post you link to has nothing to do with hosts files, he is saying that you likely aren't the GNAA troll, what does that have to do with your software?
Perhaps if you are trying to post links to people supporting you, you should actually post links to people supporting you?
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
You are funny, you wish you could even get things right once, but yet still fail utterly to prove your way out of a paper bag.
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
If you could read, you wouldn't still be arguing. It has been proven out that you cannot read repeatedly, including right here, as you didn't read any of the posts you linked to.
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
A CIA Bug.
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
I already did by identifying you as a "fuckup". Which you clearly are.
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
not sure how this is troll when it is scientifically correct. this is not a knock at anyone, simply the scientific truth
have you seen my sig? there are many others like it but none that are the same
Wow, you really are special.
When you try to compare hosts to remote DNS, you are missing the point. You should be comparing hosts to local DNS, and DNS is faster on every count.
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
It would be hilarious if you actually got something right for once, but sadly no, I will now proceed to tear your argument apart.
"except on the hard coded favorites, and even then if they make calls to non hard coded sites, they will take forever" - by Coren22 (1625475) on Tuesday December 01, 2015 @10:02AM (#51033517)
See subject: 1st of all you stupid fuck, ads I block alone buys that speed back on the RARE sub 4% times I need DNS - get it? Good!
You CANNOT compare hosts to local DNS with the same records. Yet you continue to try. The ads you block are also on the DNS side, so how can you count the time you save there? If the DNS has the exact same records as your hosts file, every site will load faster. You don't make up the time with the ads you aren't loading, as they also are not loaded with the DNS example. How can you live with such a low IQ?
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
Compared to your horribly inefficient Hosts file, even remote DNS comes out so far ahead it isn't even funny. But keep trying to claim your hosts file outperforms local DNS, when it flatly does not.
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
So, how is it a fuckup that you decide to ignore the ad blocking the local DNS server is doing in your figuring? I see a fuckup, but not on my side.
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
No it isn't.
DNS running locally is kept up to date in patches, it is not a security issue. DNS uses less resources and speeds your browsing, leading to more power savings. Why would you setup a separate system? https://www.isc.org/downloads/ The need for the locally setup DNS is the exact same need as the need for your terrible hosts file, so that argument is silly. Keep reaching and moving the goal posts.
due to your LIMITED MENTALLY DAMAGED GOOD ASSBURGERS BRAIN being only able to hold 1 of MANY variable factors in play @ a time
Stay classy.
(sub 4% of the time ONLY for me due to hardcoded favorites in hosts @ the TOP of it cached in RAM locally)? Adblocking gains me back lookup speeds if a total miss & I have to hit DNS remotely.
You mean the same ad blocking you gain with a local dns setup with the same entries? Or did your ability to hold onto only one variable catch you again?
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
Less is more, I totally agree! This is why I suggest running BIND with the entries, as it is more efficient on power, and faster in processing. It uses way less power and time, and speeds up your browsing many fold over your 2 million plus record hosts file!
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
This is garbage. Literally this entire thread is APK spewing foam and cohen22 shooting him with a nerf gun.
You know what they call people like you? Zealots. You can't see that you have already lost your argument, so you keep making the same points over and over, despite them already being proved wrong. Keep up the crusade!
BIND can run on any computer, including desktops. It therefore uses less power/resources than your hosts file, as your name resolution is sped up many fold, so you don't wait on your queries as long. It also can be setup to block the very same records, so it is still faster than your ad blocking, as it is doing that as well. So, when you have an actual argument against BIND, let me know, until then, you have lost, go home and cry into your pillow.
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
Absolutely not me.
Almost wish it was, though.
Il n'y a pas de Planet B.
Darn, I was just starting to enjoy your work, seemed to shaping up nicely.
Il n'y a pas de Planet B.
Wow, a -1, Informative. First time for everything, heh.
Il n'y a pas de Planet B.