DEF CON 33 - HTTP 1 1 Must Die! The Desync Endgame  - James 'albinowax' Kettle

DEF CON 33 - HTTP 1 1 Must Die! The Desync Endgame - James 'albinowax' Kettle

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 36:32

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

HTTP 1.1 has a fundamental flaw where request isolation is broken, making desync attacks inevitable. Despite known vulnerabilities for over six years, the industry has only patched detection methods rather than fixing the actual protocol issues.

Key Takeaways:
• Desync endgame makes systems appear secure until tiny changes reveal massive vulnerabilities, as shown when a Cloudflare flaw potentially exposed 24 million websites
• HTTP 1.1's complexity when proxied creates multiple attack vectors, including "zero CL desync" attacks previously considered impossible
• The Expect header introduces new desync attack classes affecting major platforms like GitLab and Netlify
• Recent desync vulnerabilities earned over $350,000 in bug bounties, demonstrating ongoing financial impact

The only real solution is migrating to HTTP/2 or HTTP/3 for upstream connections, as they lack HTTP 1.1's fundamental request isolation flaws.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hello. Hello, and welcome to HTTP 1.1 Must Die, the desync endgame. Have you ever had a good thing that went a bit too far? Maybe you got more than you bargained for. This is the fourth year that I've spent researching HTTP desync attacks. And so, I thought I knew what I was going to find. The plan was to neatly wrap up a well understood attack class by finding some weird bugs and niche flaws in obscure systems. The long tale of desync attacks. But what I actually discovered changed both my perspective and the title of this presentation. So today in this session, I'm going to share tools and techniques to enable you to embrace the neverending horror of HTTP 1.1, navigate the desync endgame, and convince the rest of the world that it's time for HTTP1 to die. This started back in 20 2019 whe…