The Entire Internet is Broken

The Entire Internet is Broken

🎙 John Hammond 👥 2.2M 📅 August 25, 2025 ⏱ 22 min 👁 52K 📄 expert opinion 🧭 2026-08-17
Available in: English (current) Français

Keywords

HTTP/1.1request smugglingdesynccache poisoningweb security

Summary

In this video, John Hammond interviews James Kettle, Director of Research at PortSwigger, about his latest research on HTTP/1.1 vulnerabilities. Kettle explains that HTTP/1.1 is inherently insecure due to poor request isolation, leading to request smuggling attacks. He demonstrates a new scanning technique using the open-source tool HTTP Request Smuggler, which can identify parser discrepancies between front-end and back-end servers. The research reveals that many defenses are ineffective, and attackers can exploit these flaws to perform cache poisoning, response queue poisoning, and even compromise CDNs like Cloudflare and Akamai, affecting millions of websites. Kettle emphasizes that the only real solution is to move to HTTP/2 for upstream connections. The video also highlights the financial impact, with over $350,000 earned in bug bounties, and discusses the importance of raising awareness in the security community.

133 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into the current state of HTTP/1.1 security, backed by real-world examples and demonstrations. Kettle’s argumentation is solid, as he explains the technical details of request smuggling and shows how seemingly minor discrepancies can lead to severe vulnerabilities. The demonstration of the scanning tool adds practical value, showing how these issues can be identified. The discussion is well-structured, moving from the basics to advanced exploitation techniques, making it accessible to a technical audience.

Scientific Rigor, Source Quality, Title Accuracy

The video references James Kettle’s research and the HTTP/1.1 must die website, which provides a white paper and labs. The sources are credible, as Kettle is a well-known researcher in the field. The title is somewhat sensational but accurately reflects the content’s claim that HTTP/1.1 is fundamentally broken. The video does not cite external sources beyond the research itself, but the information is presented with technical depth and practical demonstrations, enhancing its credibility.

165 words

Title / Content Match

The title is somewhat sensational but accurately reflects the content's claim that HTTP/1.1 is fundamentally broken and affects a large portion of the internet.

Quality & Reliability

8/10

Interview with James Kettle, a recognized security researcher, discussing his latest research on HTTP/1.1 vulnerabilities. The claims are supported by references to real-world exploits and bounties, but the video is primarily a discussion and demonstration rather than a peer-reviewed study.

Key Moments

Cited Sources

  • HTTP/1.1 Must Die — James Kettle's research page with white paper and labs.
  • PortSwigger — Sponsor and developer of Burp Suite, the tool used in the demonstration.
  • Just Hacking Training — Training platform by John Hammond.
  • Newsletter — John Hammond's newsletter for updates.
  • CodeCrafters — Affiliate link for learning to code.
  • OpenVPN — Affiliate link for hosting VPN.
  • CyberDefenders — Affiliate link for blue team training.

Concurring Sources

  • PortSwigger Research — PortSwigger's research page, which includes related articles on request smuggling and desync attacks.
  • HTTP Request Smuggler Tool — Open-source tool used in the video for detecting request smuggling vulnerabilities.

Dissenting Sources

  • HTTP/1.1 is fine for simple use cases — Some commenters argue that HTTP/1.1 is acceptable for simple, non-sensitive applications, but this does not negate the vulnerabilities discussed.

Contribution & Novelties

The video provides an in-depth look at the latest research on HTTP/1.1 vulnerabilities, highlighting that despite years of awareness, the protocol remains fundamentally broken. The demonstration of the new scanning tool and the zero-CL desync technique offers practical insights for security researchers. The discussion on the scale of impact (30 million websites) underscores the urgency of addressing these issues.

Pour aller plus loin :

  • HTTP Request Smuggling — Official PortSwigger resource on request smuggling.
  • HTTP/2 — Overview of HTTP/2 and its advantages over HTTP/1.1.
  • Desync Attacks — Research paper by James Kettle on desync attacks.

95 words

Radar Profile

The radar profile shows high scores in quantity and quality of information, reflecting the depth and credibility of the content. The technical level is high, indicating that the video is aimed at a technical audience. The overall reliability is strong, supported by the researcher's expertise and real-world examples.

Reliability 8/10

💬 Positif. Sur les 30 commentaires analysés, la majorité exprime un intérêt et une appréciation pour le contenu, certains partageant des préoccupations pratiques sur l'utilisation de HTTP/1.1, mais dans l'ensemble, le climat est favorable et engageant.