3 ms·
This is just my purely anecdotal observation and may not be useful but for my hobby servers blogs, chat servers, etc... I only accept HTTP/2.0. This blocks all
by LinuxBender 2y ago
This is just my purely anecdotal observation and may not be useful but for my hobby servers blogs, chat servers, etc... I only accept HTTP/2.0. This blocks all the older and poorly maintained bots. All modern browsers can use HTTP/2.0. If I had some API exposed then I would probably make an exception for that URL as some of the API tools also use old HTTP libraries. For what it's worth I have never had an issue with someone not being able to reach any of my sites using a real browser. Ultimately the answer to your question depends on analyzing your logs for legit traffic.
I would not do this in an enterprise environment without extension logging, monitoring, investigation into IP's using != HTTP/2.0 and customer notifications, maybe even customer discussion on community portals. Another place this will not work is Tor hidden sites unless you have a signed onion domain using HTTPS.
Nginx example using return code 444: [1][2]
if ($server_protocol != HTTP/2.0) { return 444; }
[1] - https://nginx.org/en/docs/http/ngx_http_rewrite_module.html#return https://nginx.org/en/docs/http/ngx_http_rewrite_module.html#...
[2] - https://stackoverflow.com/questions/41421111/http-444-no-response-instead-of-404-403-error-pages https://stackoverflow.com/questions/41421111/http-444-no-res...