4 ms·
What a terrible stance for a company like Fastly to take: More debatable perhaps is Via, which is required (by RFC7230) to be added to the response by any prox
by randomdrake 8y ago
What a terrible stance for a company like Fastly to take:
More debatable perhaps is Via, which is required (by RFC7230) to be added to the response by any proxy through which it passes to identify the proxy. This can be something useful like the proxy’s hostname, but is more likely to be a generic identifier like “vegur”, “varnish”, or “squid”. Removing (or not setting) this header is technically a spec violation, but no browsers do anything with it, so it’s reasonably safe to get rid of it if you want to.
Actually, it isn’t “debatable,” since the debate occurred, and a decision was made, and published. That’s what RFCs are for.
To ignore them with such wanton disregard speaks volumes.
Edit: to clarify, I didn't mean that RFCs should not be debated at all, only that disregarding this because "no browsers do anything with it" didn't seem like a good justification or stance.
- tcd 8y agoNot really. Standards are nice, but as time goes on, things change, and we should NEVER only change things 'once a standard says so'. The web is an ever evolving platform, and standards are loosely respected these days anyway. Heck, browsers aren't a standard themselves!
- SahAssar 8y agoBy that logic there isn't any point to standards at all. If we all are supposed to ignore them when we feel like it then what's the point of having them at all? If there is a standard published for something, follow it or publish your own RFC. Don't just nitpick the bits you want and break clients in the process.
- tptacek 8y agoThey're provided as guidance. They aren't some kind of internet law. Sometimes contravening standards is harmful; sometimes it's helpful. It's not productive to point at them as if they were dispositive in debates.
- quickben 8y agoNot really. https://tools.ietf.org/html/rfc791 https://tools.ietf.org/html/rfc791 ^ Was burned in hardware all over the planet.
- tptacek 8y agoPeople play games with IP all the time.
- scrollaway 8y agoSure, but there isn't a big company with clout saying "Hey, you should deviate from RFC791". I agree that standards can and should be replaced/amended to over time, but I kinda see what GP's point is getting at.
- pvg 8y agoDropping Via from a response is roughly in the same category as ignoring the TCP Urgent flag. Most widely used standards have vestigial bits.
- AstralStorm 8y agoA lot of hardware silently edits TOS flags, causing trouble with ECN and diff-serv... Ignoring is usually fine. Dropping is not.
- xg15 8y agoNope. If web standards worked, the benefits would be a stable platform where you can easily create new software that both produced or consumed content without breaking anything. Of course that isn't what is happening at all. Instead we're having the usual heap of politics and ever-faster update cycles. So I'd agree to say that web standards failed - but not that they were meant as a guidiance in the first place.
- triska 8y ago
- KMag 8y ago> Don't just nitpick the bits you want <nitpick> Only people who like lice eggs nitpick the bits they want. Others pick-and-choose. </nitpick> https://www.vocabulary.com/dictionary/nit https://www.vocabulary.com/dictionary/nit
- bovermyer 8y agoYou, sir, have achieved a new level of pedantic.
- deleted 8y ago[deleted]
- nstart 8y agoI do disagree with the parent's wording that it isn't "debatable". At the same time, I think the point trying to be made is that the article disregards the debates made for it. This seems to show itself in the fact that the article talks mainly of how browsers do not use Via. The problem being that the debate around the RFC was for an entirely different use case. As per the RFC spec, a lot of it was around protocol capabilities. Thus it may not be useful to the browser. But the article saying that its usage is debatable in this context is very wrong.
- deaps 8y agoSo then re-write and submit an RFC...or go to IETF and join a WG - be open to discussion and speak up about what needs changed. A MUST is a MUST, in my opinion - and too often there are serious issues in (web) communication because people ignore them as they see fit. In either event - no one is saying that you should wait to change an RFC (or wording in an RFC) until it's fully deprecated and completely not in use - but a lot of people use RFC's for researching issues, especially in areas they are not 100% familiar with. Coming across a MUST and seeing that some software vendor or hardware vendor doesn't follow it is all too common. This delays certain projects by weeks, sometimes longer, and costs the involved companies lots of money. RFC's exist for a reason...because the approved standards are just expected to be followed when creating new things.
- MichaelGG 8y agoSome things are just wrong. I've implemented SIP, a horrible standard. Lots of compatibility issues just from their insistence on a "human friendly" text format alone. At any rate there's lots of things you just have to ignore, drop, reject, and otherwise muck about with in order to run a sane network. These standards are not written with software experience. They're written much in a vacuum and out of touch. This varies widely across RFCs so it might not apply to RFCs you like. Example of a MUST for SIP and HTTP: line folding and comments in headers. Apart from being crap for performance (so much for being able to zero-copy a header value as just a pointer+len) there's zero legitimate use for these "features" of the syntax. Simply rejecting such messages is in your best interest as a network operator.
- CodyReichert 8y agoThis specific point got me as well: I can't really get behind a company - especially a CDN company - telling people to break the specific because "no browsers don't do anything with it." That is, honestly, really bad advice and I can't take any of their other points seriously.
- liveoneggs 8y agoI think this blog is more of an editorial piece considering that fastly will insert two 'Via: 1.1 varnish' with shielding enabled plus a range of additional X- headers. :)
- tinus_hn 8y agoAn RFC is a Request for Comments, an invitation to debate. Anyone can publish an RFC.
- deaps 8y agoRight - then IETF adopts approved RFC's and publishes them as internet standards. What we're discussing in this thread are accepted / approved internet standards - not just some random RFC that some dude tossed up on a work group.
- tinus_hn 8y agoIt’s not like there is some kind of internet police that’ll come after you if you don’t follow the RFCs, whether IETF approves them or not. You can decide to follow them all the way, partly or not at all. Or you can debate them as much as you want, or even publish a new and improved version and perhaps people will decide to follow that instead. Or perhaps they’ll just do whatever they feel like.
- ddalex 8y agoI actually read this whole thing as: we don't disable this ourselves. But if you're using us as the last layer before the user agent, you can dump this header. And our Varnish language makes it easy.