3 ms·
Exactly! One of the big pain points in HTTP/1.1 is that you don't know who the client is. You get six or more connections at a time, so you have to correlate
by bsdetector 10y ago
Exactly! One of the big pain points in HTTP/1.1 is that you don't know who the client is. You get six or more connections at a time, so you have to correlate them together using cookies or other ids. It's easy to proxy and cache so you don't know if it's a single person on the other end or many people. Since there are so many connections they close in a minute or less so you have figure out which connections are the same user from earlier.
Now with HTTP/2 there's only one connection and it stays open for a long time so that connection info can be used to identify a client session. It's TLS only so much less likely to be a proxy, since the proxy needs a trusted certificate added to the browser. And also connections to a third-party domain are shared across all pages, so if you are doubleclick.net you know the same user is browsing different sites.
The new protocol makes tracking users much easier and fixes a huge privacy problem in HTTP/1.1.