Sign in

Lucas Pardue

@simmervig.org
1.1K followers 171 following 76 posts

Protocol nerd at Apple. Ex-Cloudlfare. QUIC and WebTransport WG co-chair. Thoughts belong to me.

PostsRepliesMedia
Lucas Pardue @simmervig.org · 09/08/2026
I've written over 7000+ words on the past, present and future of HTTP integrity (aka digest fields). If you never heard of RFC 9530, Content-Digest or Repr-Digest here's my best attempt at describing them with examples and code repro snippets. lucaspardue.com/2026/08/08/h...
lucaspardue.com
HTTP Integrity Digests: Past, Present, and Future
The core HTTP specifications don’t define their own means of providing integrity. Although “hop-by-hop” protocols underneath HTTP, such as TLS or QUIC, provide integrity for HTTP message transactions,...
261
Lucas Pardue @simmervig.org · 04/08/2026
v1 of HTTP Integrity Demos is up at lucaspardue.com/integrity-de.... Browser-based interactive demos to help understand RFC 9530 headers like Content-Digest, Repr-Digest and more
052
Lucas Pardue @simmervig.org · 24/07/2026
QUIC connections can negotiate an idle timeout once during the handshake, and never change it. Perhaps it would make sense to make it mutable? I'm not sure! My slides from IETF 126 github.com/quicwg/wg-ma...
Eric Idle: life has a very simple plot, first you're here and then you're not
020
Lucas Pardue @simmervig.org · 14/06/2026
Forget coding, I've been vibe tabbing. Started learning bass and use songsterrs AI tool. Not perfect but has taught me more about moving around the fretboard than I imagined. For example, Rosa Walton's "halfway round the world" www.youtube.com/watch?v=OGbV... www.songsterr.com/a/wsa/rosa-w...
songsterr.com
Halfway Round The World Bass Tab by Rosa Walton | Songsterr Tabs with Rhythm
Halfway Round The World Bass Tab by Rosa Walton. Free online tab player. One accurate version. Play along with original audio
010
Lucas Pardue @simmervig.org · 12/06/2026
Starting in a couple on minutes!
000
Reposted by Lucas Pardue
Henri Helvetica 🧑🏾‍🚀🇭🇹 @henrihelvetica.bsky.social · 05/06/2026
For the 2nd time in a month, I'm welcoming an authority on protocols: @simmervig.org , QUIC and WebTransport @quicwg co-chair will join me to chat all things HTTP3, and how it speeds up all these apps you're building + shipping 📆 Friday June 12th ⏰ 1pm EST, 6pm 🇬🇧 🔗 www.youtube.com/live/TXPz94_...
SPDY stream. A yellow and green F1 race car branded with "Benton sports system" performance people projects Friday, June 12, 2026, 1 PM. Online. Two avatars of speakers.
031
Reposted by Lucas Pardue
Mark Nottingham @mnot.net · 11/05/2026
I looked through Common Crawl and found over 300,000 parseable RSS/Atom feeds, confirming that Web feeds are still a major part of the Open Web. But most aren’t high quality, and autodiscovery often points users at stale or abandoned feeds. mnot.net/blog/2026/feed-survey
051
Lucas Pardue @simmervig.org · 24/01/2026
Renewed my @fastmail.com subscription after 2 years of it just working and no other bullshit. Feels good to pay for stuff like this.
010
Reposted by Lucas Pardue
Internet Engineering Task Force @ietf.org · 16/01/2026
Forty years ago, 21 people gathered for the first meeting of what became the IETF. Today, nearly 8000 IETF participants from around the world collaborate in more than 100 working groups and every day billions of people use technologies developed in the IETF. www.ietf.org/blog/ietf-40
14221
Lucas Pardue @simmervig.org · 23/12/2025
I'm watching Angel as a mindless guilty pleasure. In S2 E9, they seem to have forgotten to green screen the demon's lower half after it got chopped off. Not sure if this is due to 16:9 aspect or if the booboo was aired
A demon with green lucrative pants on being dragged along the floor .
010
Lucas Pardue @simmervig.org · 31/10/2025
HTTP/2-based DoS attacks are here to stay. Many implementations are hardened to them. Quirky behaviour can trigger defenses and cause ENHANCE_YOUR_CALM. Read one of my latest trips down a debugging rabbit hole. blog.cloudflare.com/go-and-enhan...
blog.cloudflare.com
Go and enhance your calm- demolishing an HTTP:2 interop problem
HTTP/2 implementations often respond to suspected attacks by closing the connection with an ENHANCE_YOUR_CALM error code. Learn how a common pattern of using Go's HTTP/2 client can lead to unintended ...
030
Reposted by Lucas Pardue
Sergey Chernyshev @sergeyche.dev · 30/10/2025
Glad to announce that my team at @cloudflare.social released a 1.0.0 version of a cross-browser web performance testing agent that supports Chrome, Firefox, Safari and Edge. Thank you to @tkadlec.bsky.social for making it happen and writing most of the code so far! github.com/cloudflare/t...
github.com
GitHub - cloudflare/telescope: Cross-browser web performance testing agent
Cross-browser web performance testing agent. Contribute to cloudflare/telescope development by creating an account on GitHub.
03312
Lucas Pardue @simmervig.org · 29/10/2025
About 6 months ago Louis Navarre reached out to report some DoS-related vulnerabilities in quiche's ack processing. We fixed it up and saw no evidence that the vulnerabilities had been exploited. Check out the deep dive blog post: blog.cloudflare.com/defending-qu...
blog.cloudflare.com
Defending QUIC from acknowledgement-based DDoS attacks
We identified and patched two DDoS vulnerabilities in our QUIC implementation related to packet acknowledgements. Cloudflare customers were not affected. We examine the
021
Lucas Pardue @simmervig.org · 22/09/2025
Ed Davey pointing at TamboRambo thumbs upping Ed Davey
000
Reposted by Lucas Pardue
Mike English @englishm.bsky.social · 22/08/2025
Some news.. blog.cloudflare.com/moq/
blog.cloudflare.com
MoQ: Refactoring the Internet's real-time media stack
For years, developers have been stitching together multiple protocols for real-time media, trading latency for scale and simplicity. Media over QUIC (MoQ) is a new IETF standard that resolves this con...
2105
Lucas Pardue @simmervig.org · 12/08/2025
It would be funny it wasn't actually true
010
Lucas Pardue @simmervig.org · 25/07/2025
Hehe
Android notification from YouTube for IETF session
000
Lucas Pardue @simmervig.org · 20/07/2025
Watching Usyk vs. Dubois squashed into a sports bar booth in Porto with 4 randoms, 2 from London, 2 from Ukraine, was not on the bingo card. But it all worked out.
000
Lucas Pardue @simmervig.org · 16/07/2025
I can predict how these new age checks are going to go using two pictures
BBC article about porn age checks, festure image a man in bed on his phoneBBB news article about the Co-Op leak of 6.5 million customers data
010
Lucas Pardue @simmervig.org · 16/07/2025
I've heard of crackpot science. I guess the future equivalent is grokbot science
000
Lucas Pardue @simmervig.org · 09/07/2025
I'm excited to announce I'll be at gRPC Conf on August 26 2025 to present how Cloudflare built its gRPC support first launched in 2020, and how we've been adding gRPC over HTTP/3 support lately. Session details at: grpcconf2025.sched.com/event/26BMY/...
grpcconf2025.sched.com
gRPC Conf 2025: Bringing HTTP/3 To gRPC at Cloudflare Sc...
View more about this event at gRPC Conf 2025
020
Lucas Pardue @simmervig.org · 07/07/2025
Hot off the press, happy to announce the adoption and publication of datatracker.ietf.org/doc/html/dra... Unencoded Digest is one of the missing pieces for certain use cases like the W3C signature-based integrity work. Helping to cover cases where encoding and transform independence are paramount
datatracker.ietf.org
HTTP Unencoded Digest
The Repr-Digest and Content-Digest integrity fields are subject to HTTP content coding considerations. There are some use cases that benefit from the unambiguous exchange of integrity digests of unenc...
040
Reposted by Lucas Pardue
Colin Perkins @csperkins.org · 16/06/2025
An IRTF Retrospective – in which I reflect upon my time as Chair of the IRTF csperkins.org/standards/20...
csperkins.org
Colin Perkins : Standards News : An IRTF Retrospective
031
Lucas Pardue @simmervig.org · 17/05/2025
Wouldn't call it vibe coding but I've been using some AI to add features to throwaway test toys written in Go to Get Shit Done. Look out for some future updates about the $thing these toys are helping to make robust.
000
Lucas Pardue @simmervig.org · 15/05/2025
Using Internet standards to improve the the way automed traffic / bots can interact with the world. Namely two methods: HTTP Signatures (RFC 9421) and req mTLS flag (draft-jhoyla-req-mtls-flag) blog.cloudflare.com/web-bot-auth/
blog.cloudflare.com
Forget IPs: using cryptography to verify bot and agent traffic
Bots now browse like humans. We're proposing bots use cryptographic signatures so that website owners can verify their identity. Explanations and demonstration code can be found within the post.
041
Lucas Pardue @simmervig.org · 11/05/2025
Enjoying Kagi quite a bit
020
Lucas Pardue @simmervig.org · 09/05/2025
AI slop has gotta stop. Hysterical* thing with this bullshit report to curl's hackerone (hackerone.com/reports/3125...) "HTTP/3 Stream Dependency Cycle Exploit" is we took great pains to standardize a priortization scheme that entirely did away with stream dependencies. * not the jovial definition
hackerone.com
Unsupported Browser | HackerOne
010
Lucas Pardue @simmervig.org · 08/05/2025
My team at Cloudflare are hiring mid-level and senior engineers to help us go deep on network protocols (HTTP, QUIC, TLS etc.) as we build and deploy our new Rust-based proxy. More details (including location) over on LinkedIn: www.linkedin.com/posts/lucasp...
linkedin.com
The Cloudflare Protocols team is hiring for a number of roles! Come work… | Lucas Pardue
The Cloudflare Protocols team is hiring for a number of roles! Come work with me and my awesome manager Michelle Torres 🏳️‍🌈. We're looking for experienced mid-level and senior engineers to go d...
142
Lucas Pardue @simmervig.org · 07/05/2025
Check out this cool shit
051
Lucas Pardue @simmervig.org · 26/04/2025
Gearing up to chair the next QUIC WG meeting be like
Paraphrasing Rick Rubin and saying "I have no technical ability. And know nothing about protocol minutae."
020
Lucas Pardue @simmervig.org · 25/04/2025
Multipath Extension for QUIC is now in Working Group Last Call. datatracker.ietf.org/doc/draft-ie...
030
Lucas Pardue @simmervig.org · 14/04/2025
Welcome back, now fix my stuff plz
040
Lucas Pardue @simmervig.org · 20/03/2025
Tomorrow's presentation to the HTTP WG is going to be a hoot
Triptych of freuds's I'd model, petshop boys, and half of the A-team
010
Lucas Pardue @simmervig.org · 08/03/2025
Discovered a pinball gem on my local town www.pinballrepublic.com
Multiple pinball machines
170
Lucas Pardue @simmervig.org · 01/03/2025
All logs lead to qlog
010
Lucas Pardue @simmervig.org · 21/02/2025
I ordered 2 of these, look amazing.
021
Lucas Pardue @simmervig.org · 19/02/2025
Second patent cube has arrived, so I guess it can formally be called a collection.
Two metal and plastic cubes on a shelf. On the front of each cube is a printed Lava lamp, with patent number and inventor name.
4200
Lucas Pardue @simmervig.org · 10/02/2025
Broadcast IP never fails to amaze
140
Lucas Pardue @simmervig.org · 07/02/2025
On January 23, 2025, Cloudflare was notified via its Bug Bounty Program of a vulnerability in Cloudflare’s Mutual TLS (mTLS) implementation. Read the blog post for details of the vulnerability and how my colleagues put in place mitigations in short order. blog.cloudflare.com/resolving-a-...
blog.cloudflare.com
Resolving a Mutual TLS session resumption vulnerability
Cloudflare patched a Mutual TLS (mTLS) vulnerability (CVE-2025-23419) reported via its Bug Bounty Program. The flaw in session resumption allowed client certificates to authenticate across different z...
051
Lucas Pardue @simmervig.org · 02/01/2025
Finally cracked some wasm stuff that has been on the bottom of the todo list for a while
000
Lucas Pardue @simmervig.org · 30/12/2024
h3i is a command line tool and Rust library designed for low-level testing and debugging of HTTP/3, which runs over QUIC. We've replaced our hodgepodge of test tools with it and caught server bugs in the process. Deep Dive at blog.cloudflare.com/h3i
080
Lucas Pardue @simmervig.org · 25/12/2024
Annual Picard youtu.be/oiSn2JuDQSc?...
041
Lucas Pardue @simmervig.org · 19/12/2024
I got something in the pipeline for ya
100
Lucas Pardue @simmervig.org · 14/12/2024
That feeling when you spent weeks of people time investigating a problem, then find an open bug from ~10 years ago that sounds eerily the same: issues.chromium.org/issues/41161...
Chromium bug tracker showing " Chrome SPDY window deadlock downloading multiple videos"
140
Reposted by Lucas Pardue
Robin Marx @programmingart.bsky.social · 10/12/2024
This year, I again had the honour of authoring the HTTP chapter of the Web Almanac: almanac.httparchive.org/en/2024/http It's full of interesting stats on technologies like HTTP/3, DNS HTTPS records, preloads, 103 Early Hints and the FetchPriority API. It also has Pirates 🏴‍☠️ and Marry Poppins 🌂!
almanac.httparchive.org
HTTP | 2024 | The Web Almanac by HTTP Archive
The HTTP chapter of the 2024 Web Almanac covers data on historical versions of HTTP used across the web, as well as the uptick in adoption of HTTP/2 and HTTP/3 from alt-svc and DNS HTTPS records. Addi...
23613
Lucas Pardue @simmervig.org · 07/12/2024
I am once again writing parsing code for Chrome netlogs. The format for QUIC transport parameters is some funky ass string.
040
Lucas Pardue @simmervig.org · 06/12/2024
Think subresource integrity is good in theory but sucks in practice because the hashes change too frequently? New approach here that removes some if the pains
010
Lucas Pardue @simmervig.org · 29/11/2024
Step 1
Domain registration on Cloudflare for simmervig.org
130
Lucas Pardue @simmervig.org · 29/11/2024
At the same time Disney+ told me the price of renewal would close to double and I decided to cancel it completely. YouTube offered me a free 2 month trial or premium. I'm feeling weirdly conflicted that I actually seem to enjoy YouTube more now and might continue it on..
220
Lucas Pardue @simmervig.org · 26/11/2024
www.rockpapershotgun.com/recent-chang... So it turns out for the last couple of weeks, Firefox's tracking protection had completely hidden the RPS new comment system. And there I was thinking they'd just turned comments off altogether.
rockpapershotgun.com
Comments for "Recent changes to our comments system"
PC gaming news, previews, reviews, opinion.
000