home.social

#forwarded — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #forwarded, aggregated by home.social.

fetched live
  1. It's disheartening that 25 years after the Web Standards Project (WaSP) was established, and 10 years after it was shut down with @Aaron's famous "Our work here is done” post, standards still have to be fought for with violence in order to be adopted.

    webstandards.org/2013/03/01/ou

    #Microsoft #Azure #HTTP #Forwarded #Header #Standard #Standards #Standardization #Standardisation #RFC #IETF

  2. It's disheartening that 25 years after the Web Standards Project (WaSP) was established, and 10 years after it was shut down with @Aaron's famous "Our work here is done” post, standards still have to be fought for with violence in order to be adopted.

    webstandards.org/2013/03/01/ou

    #Microsoft #Azure #HTTP #Forwarded #Header #Standard #Standards #Standardization #Standardisation #RFC #IETF

  3. Nothing being properly specified, the cardinality of the different `X-Forwarded-*` headers when used in combination, is also entirely undefined. Which values go with which when several `X-Forwarded-Host` and `X-Forwarded-Proto` are specified, for instance? How do you pair them up? Who knows! 🤷🏽‍♂️

    However, the most important problem is that these headers impose a large security and privacy risk. Not having a common, evolving specification in which these security and privacy risks are discussed, and mitigated, is a major threat to the security of server infrastructure and the privacy of the users of that infrastructure.

    developer.mozilla.org/en-US/do

    #Microsoft #Azure #HTTP #Forwarded #Header #Standard #Standards #Standardization #Standardisation #RFC #IETF

  4. Nothing being properly specified, the cardinality of the different `X-Forwarded-*` headers when used in combination, is also entirely undefined. Which values go with which when several `X-Forwarded-Host` and `X-Forwarded-Proto` are specified, for instance? How do you pair them up? Who knows! 🤷🏽‍♂️

    However, the most important problem is that these headers impose a large security and privacy risk. Not having a common, evolving specification in which these security and privacy risks are discussed, and mitigated, is a major threat to the security of server infrastructure and the privacy of the users of that infrastructure.

    developer.mozilla.org/en-US/do

    #Microsoft #Azure #HTTP #Forwarded #Header #Standard #Standards #Standardization #Standardisation #RFC #IETF

  5. It’s sad to see Microsoft Azure reenforcing the entrenchment of the non-standard, unspecified, buggy and insecure `X-Forwarded-*` headers:

    learn.microsoft.com/en-us/azur

    …instead of the standard `Forwarded` header specified in RFC 7239:

    rfc-editor.org/rfc/rfc7239.htm

    What's the problem with the `X-Forwarded-*` headers, you may ask? Well, for starters, there isn’t a specification in existence that tells implementers what to expect of their contents.

    There's sort of a least common multiple of allowed values adhering to a sort of familiar HTTP header syntax, but no specification laying out "this is supported, period" exists. This is an interoperability nightmare in itself. Should the headers support one or multiple values? Who knows! 🤷🏽‍♂️

    #Microsoft #Azure #HTTP #Forwarded #Header #Standard #Standards #Standardization #Standardisation #RFC #IETF

  6. It’s sad to see Microsoft Azure reenforcing the entrenchment of the non-standard, unspecified, buggy and insecure `X-Forwarded-*` headers:

    learn.microsoft.com/en-us/azur

    …instead of the standard `Forwarded` header specified in RFC 7239:

    rfc-editor.org/rfc/rfc7239.htm

    What's the problem with the `X-Forwarded-*` headers, you may ask? Well, for starters, there isn’t a specification in existence that tells implementers what to expect of their contents.

    There's sort of a least common multiple of allowed values adhering to a sort of familiar HTTP header syntax, but no specification laying out "this is supported, period" exists. This is an interoperability nightmare in itself. Should the headers support one or multiple values? Who knows! 🤷🏽‍♂️

    #Microsoft #Azure #HTTP #Forwarded #Header #Standard #Standards #Standardization #Standardisation #RFC #IETF

  7. Are you annoyed by my #forwarded #retweets from #birdside #twitter? Mastodon offers filters:
    "Gear-icon > Filters"

    Just put one in place, filtering "RT: @" and you'll never see rt-crossposts from me again!

    #servicetoot