Sign in

Lucas Pardue

@simmervig.org
1.1K followers 171 following 76 posts

Protocol nerd at Apple. Ex-Cloudlfare. QUIC and WebTransport WG co-chair. Thoughts belong to me.

PostsRepliesMedia
Lucas Pardue @simmervig.org · 09/08/2026
Resumable uploads are another use case (see datatracker.ietf.org/doc/draft-ie...). It would be optional though. We just recently removed the digest text in the draft because it was becoming clear it needed more fleshing out and makes sense to put in its own document, likely mentioning Patched-Digest
ietf.org
Resumable Uploads for HTTP
HTTP data transfers can encounter interruption due to reasons such as canceled requests or dropped connections. If the intended recipient can indicate how much of the data was processed prior to inter...
020
Lucas Pardue @simmervig.org · 09/08/2026
Payment systems based on HTTP are a more down-to-earth example. Having a way to sign a request or response that protects the end-to-end integrity is very useful.
ietf.org
Resumable Uploads for HTTP
HTTP data transfers can encounter interruption due to reasons such as canceled requests or dropped connections. If the intended recipient can indicate how much of the data was processed prior to inter...
120
Lucas Pardue @simmervig.org · 09/08/2026
The work at BBC R&D had a design where multicast would deliver bulk data and any losses would be repaired via a unicast CDN. Having a standard way to do representation digest when fetching parts from multiple sources is cool. Lots of custom approaches do similar, or attempt to abuse Content-MD5
120
Lucas Pardue @simmervig.org · 09/08/2026
I've written over 7000+ words on the past, present and future of HTTP integrity (aka digest fields). If you never heard of RFC 9530, Content-Digest or Repr-Digest here's my best attempt at describing them with examples and code repro snippets. lucaspardue.com/2026/08/08/h...
lucaspardue.com
HTTP Integrity Digests: Past, Present, and Future
The core HTTP specifications don’t define their own means of providing integrity. Although “hop-by-hop” protocols underneath HTTP, such as TLS or QUIC, provide integrity for HTTP message transactions,...
261
Lucas Pardue @simmervig.org · 04/08/2026
v1 of HTTP Integrity Demos is up at lucaspardue.com/integrity-de.... Browser-based interactive demos to help understand RFC 9530 headers like Content-Digest, Repr-Digest and more
052
Lucas Pardue @simmervig.org · 24/07/2026
QUIC connections can negotiate an idle timeout once during the handshake, and never change it. Perhaps it would make sense to make it mutable? I'm not sure! My slides from IETF 126 github.com/quicwg/wg-ma...
Eric Idle: life has a very simple plot, first you're here and then you're not
020
Lucas Pardue @simmervig.org · 14/06/2026
Forget coding, I've been vibe tabbing. Started learning bass and use songsterrs AI tool. Not perfect but has taught me more about moving around the fretboard than I imagined. For example, Rosa Walton's "halfway round the world" www.youtube.com/watch?v=OGbV... www.songsterr.com/a/wsa/rosa-w...
songsterr.com
Halfway Round The World Bass Tab by Rosa Walton | Songsterr Tabs with Rhythm
Halfway Round The World Bass Tab by Rosa Walton. Free online tab player. One accurate version. Play along with original audio
010
Lucas Pardue @simmervig.org · 12/06/2026
Starting in a couple on minutes!
000
Reposted by Lucas Pardue
Henri Helvetica 🧑🏾‍🚀🇭🇹 @henrihelvetica.bsky.social · 05/06/2026
For the 2nd time in a month, I'm welcoming an authority on protocols: @simmervig.org , QUIC and WebTransport @quicwg co-chair will join me to chat all things HTTP3, and how it speeds up all these apps you're building + shipping 📆 Friday June 12th ⏰ 1pm EST, 6pm 🇬🇧 🔗 www.youtube.com/live/TXPz94_...
SPDY stream. A yellow and green F1 race car branded with "Benton sports system" performance people projects Friday, June 12, 2026, 1 PM. Online. Two avatars of speakers.
031
Reposted by Lucas Pardue
Mark Nottingham @mnot.net · 11/05/2026
I looked through Common Crawl and found over 300,000 parseable RSS/Atom feeds, confirming that Web feeds are still a major part of the Open Web. But most aren’t high quality, and autodiscovery often points users at stale or abandoned feeds. mnot.net/blog/2026/feed-survey
051
Lucas Pardue @simmervig.org · 24/01/2026
Renewed my @fastmail.com subscription after 2 years of it just working and no other bullshit. Feels good to pay for stuff like this.
010
Reposted by Lucas Pardue
Internet Engineering Task Force @ietf.org · 16/01/2026
Forty years ago, 21 people gathered for the first meeting of what became the IETF. Today, nearly 8000 IETF participants from around the world collaborate in more than 100 working groups and every day billions of people use technologies developed in the IETF. www.ietf.org/blog/ietf-40
14221
Lucas Pardue @simmervig.org · 30/12/2025
Depending on the HTTP version, you can override priroty scheduler with more fine grain control via workers / origin header e.g. invoke a more serial order, or do banded round robin
220
Lucas Pardue @simmervig.org · 27/12/2025
Nice. We use aasvg for some IETF docs
110
Lucas Pardue @simmervig.org · 23/12/2025
I'm watching Angel as a mindless guilty pleasure. In S2 E9, they seem to have forgotten to green screen the demon's lower half after it got chopped off. Not sure if this is due to 16:9 aspect or if the booboo was aired
A demon with green lucrative pants on being dragged along the floor .
010
Lucas Pardue @simmervig.org · 31/10/2025
HTTP/2-based DoS attacks are here to stay. Many implementations are hardened to them. Quirky behaviour can trigger defenses and cause ENHANCE_YOUR_CALM. Read one of my latest trips down a debugging rabbit hole. blog.cloudflare.com/go-and-enhan...
blog.cloudflare.com
Go and enhance your calm- demolishing an HTTP:2 interop problem
HTTP/2 implementations often respond to suspected attacks by closing the connection with an ENHANCE_YOUR_CALM error code. Learn how a common pattern of using Go's HTTP/2 client can lead to unintended ...
030
Reposted by Lucas Pardue
Sergey Chernyshev @sergeyche.dev · 30/10/2025
Glad to announce that my team at @cloudflare.social released a 1.0.0 version of a cross-browser web performance testing agent that supports Chrome, Firefox, Safari and Edge. Thank you to @tkadlec.bsky.social for making it happen and writing most of the code so far! github.com/cloudflare/t...
github.com
GitHub - cloudflare/telescope: Cross-browser web performance testing agent
Cross-browser web performance testing agent. Contribute to cloudflare/telescope development by creating an account on GitHub.
03312
Lucas Pardue @simmervig.org · 29/10/2025
About 6 months ago Louis Navarre reached out to report some DoS-related vulnerabilities in quiche's ack processing. We fixed it up and saw no evidence that the vulnerabilities had been exploited. Check out the deep dive blog post: blog.cloudflare.com/defending-qu...
blog.cloudflare.com
Defending QUIC from acknowledgement-based DDoS attacks
We identified and patched two DDoS vulnerabilities in our QUIC implementation related to packet acknowledgements. Cloudflare customers were not affected. We examine the
021
Lucas Pardue @simmervig.org · 22/09/2025
Ed Davey pointing at TamboRambo thumbs upping Ed Davey
000
Reposted by Lucas Pardue
Mike English @englishm.bsky.social · 22/08/2025
Some news.. blog.cloudflare.com/moq/
blog.cloudflare.com
MoQ: Refactoring the Internet's real-time media stack
For years, developers have been stitching together multiple protocols for real-time media, trading latency for scale and simplicity. Media over QUIC (MoQ) is a new IETF standard that resolves this con...
2105
Lucas Pardue @simmervig.org · 12/08/2025
It would be funny it wasn't actually true
010
Lucas Pardue @simmervig.org · 25/07/2025
Hehe
Android notification from YouTube for IETF session
000
Lucas Pardue @simmervig.org · 25/07/2025
Insightful!
010
Lucas Pardue @simmervig.org · 20/07/2025
Watching Usyk vs. Dubois squashed into a sports bar booth in Porto with 4 randoms, 2 from London, 2 from Ukraine, was not on the bingo card. But it all worked out.
000
Lucas Pardue @simmervig.org · 16/07/2025
I can predict how these new age checks are going to go using two pictures
BBC article about porn age checks, festure image a man in bed on his phoneBBB news article about the Co-Op leak of 6.5 million customers data
010
Lucas Pardue @simmervig.org · 16/07/2025
I've heard of crackpot science. I guess the future equivalent is grokbot science
000
Lucas Pardue @simmervig.org · 09/07/2025
I'm excited to announce I'll be at gRPC Conf on August 26 2025 to present how Cloudflare built its gRPC support first launched in 2020, and how we've been adding gRPC over HTTP/3 support lately. Session details at: grpcconf2025.sched.com/event/26BMY/...
grpcconf2025.sched.com
gRPC Conf 2025: Bringing HTTP/3 To gRPC at Cloudflare Sc...
View more about this event at gRPC Conf 2025
020
Lucas Pardue @simmervig.org · 07/07/2025
Hot off the press, happy to announce the adoption and publication of datatracker.ietf.org/doc/html/dra... Unencoded Digest is one of the missing pieces for certain use cases like the W3C signature-based integrity work. Helping to cover cases where encoding and transform independence are paramount
datatracker.ietf.org
HTTP Unencoded Digest
The Repr-Digest and Content-Digest integrity fields are subject to HTTP content coding considerations. There are some use cases that benefit from the unambiguous exchange of integrity digests of unenc...
040
Reposted by Lucas Pardue
Colin Perkins @csperkins.org · 16/06/2025
An IRTF Retrospective – in which I reflect upon my time as Chair of the IRTF csperkins.org/standards/20...
csperkins.org
Colin Perkins : Standards News : An IRTF Retrospective
031
Lucas Pardue @simmervig.org · 03/06/2025
You should check out Sultans of Swim
020
Lucas Pardue @simmervig.org · 17/05/2025
Wouldn't call it vibe coding but I've been using some AI to add features to throwaway test toys written in Go to Get Shit Done. Look out for some future updates about the $thing these toys are helping to make robust.
000
Lucas Pardue @simmervig.org · 15/05/2025
Using Internet standards to improve the the way automed traffic / bots can interact with the world. Namely two methods: HTTP Signatures (RFC 9421) and req mTLS flag (draft-jhoyla-req-mtls-flag) blog.cloudflare.com/web-bot-auth/
blog.cloudflare.com
Forget IPs: using cryptography to verify bot and agent traffic
Bots now browse like humans. We're proposing bots use cryptographic signatures so that website owners can verify their identity. Explanations and demonstration code can be found within the post.
041
Lucas Pardue @simmervig.org · 11/05/2025
Enjoying Kagi quite a bit
020
Lucas Pardue @simmervig.org · 09/05/2025
AI slop has gotta stop. Hysterical* thing with this bullshit report to curl's hackerone (hackerone.com/reports/3125...) "HTTP/3 Stream Dependency Cycle Exploit" is we took great pains to standardize a priortization scheme that entirely did away with stream dependencies. * not the jovial definition
hackerone.com
Unsupported Browser | HackerOne
010
Lucas Pardue @simmervig.org · 08/05/2025
My team at Cloudflare are hiring mid-level and senior engineers to help us go deep on network protocols (HTTP, QUIC, TLS etc.) as we build and deploy our new Rust-based proxy. More details (including location) over on LinkedIn: www.linkedin.com/posts/lucasp...
linkedin.com
The Cloudflare Protocols team is hiring for a number of roles! Come work… | Lucas Pardue
The Cloudflare Protocols team is hiring for a number of roles! Come work with me and my awesome manager Michelle Torres 🏳️‍🌈. We're looking for experienced mid-level and senior engineers to go d...
142
Lucas Pardue @simmervig.org · 07/05/2025
Check out this cool shit
051
Lucas Pardue @simmervig.org · 02/05/2025
Forget Vibe coding, the new buzz is Weiss Posting
010
Lucas Pardue @simmervig.org · 02/05/2025
What's your process for bluesky posts?
100
Lucas Pardue @simmervig.org · 26/04/2025
Gearing up to chair the next QUIC WG meeting be like
Paraphrasing Rick Rubin and saying "I have no technical ability. And know nothing about protocol minutae."
020
Lucas Pardue @simmervig.org · 25/04/2025
Multipath Extension for QUIC is now in Working Group Last Call. datatracker.ietf.org/doc/draft-ie...
030
Lucas Pardue @simmervig.org · 14/04/2025
Welcome back, now fix my stuff plz
040
Lucas Pardue @simmervig.org · 20/03/2025
Tomorrow's presentation to the HTTP WG is going to be a hoot
Triptych of freuds's I'd model, petshop boys, and half of the A-team
010
Lucas Pardue @simmervig.org · 08/03/2025
Discovered a pinball gem on my local town www.pinballrepublic.com
Multiple pinball machines
170
Lucas Pardue @simmervig.org · 01/03/2025
All logs lead to qlog
010
Lucas Pardue @simmervig.org · 21/02/2025
I ordered 2 of these, look amazing.
021
Lucas Pardue @simmervig.org · 19/02/2025
Second patent cube has arrived, so I guess it can formally be called a collection.
Two metal and plastic cubes on a shelf. On the front of each cube is a printed Lava lamp, with patent number and inventor name.
4200
Lucas Pardue @simmervig.org · 14/02/2025
As Lemmy said, It's all about the game and how you play it. All about control and if you can take it. All about your debt and if you can pay it. It's all about pain and who's gonna make it.
000
Lucas Pardue @simmervig.org · 10/02/2025
Note that this isn't just a QUIC specific problem. If you listen for other UDP-based traffic using SO_REUSEPORT you might be similarly affected.
030
Lucas Pardue @simmervig.org · 10/02/2025
Broadcast IP never fails to amaze
140
Lucas Pardue @simmervig.org · 07/02/2025
On January 23, 2025, Cloudflare was notified via its Bug Bounty Program of a vulnerability in Cloudflare’s Mutual TLS (mTLS) implementation. Read the blog post for details of the vulnerability and how my colleagues put in place mitigations in short order. blog.cloudflare.com/resolving-a-...
blog.cloudflare.com
Resolving a Mutual TLS session resumption vulnerability
Cloudflare patched a Mutual TLS (mTLS) vulnerability (CVE-2025-23419) reported via its Bug Bounty Program. The flaw in session resumption allowed client certificates to authenticate across different z...
051