@mttaggart@infosec.exchange
For those who haven't seen it yet. The line of reasoning for the conclusion is similar to the argument that there is no safe way to code in Cβan argument I've made.
But I will say that the prevalence of proxies like Cloudflare are part of why this flaw is so impactful.
https://portswigger.net/research/http1-must-die