A note on QUIC protocolQUIC is a relatively new transport protocol standardized in
RFC 9000 (2021), which aims to provide secure, reliable and fast data transfer over UDP. Combined with
HTTP/3 protocol it reduces the overhead of the handshake (compared to HTTP/2 with TLS and TCP), solves the head-of-line blocking problem and makes SNI-based censorship more difficult for an on-line observer (e.g. ISP). However, it does come at a cost.
As with any attempt to improve the internet on a global scale, the adoption of the new technology takes an eternity and meets resistance from individual states if they see a risk in it; so does QUIC. Despite being implemented in the majority of browsers and server-side engines, the use of HTTP/3 is only at ~30% of the three HTTP protocols, as per
Cloudflare Radar. All this despite HTTP/3 with QUIC being
available (and enabled) for all plans.
Trying to blindly connect to port 443 via UDP would be a waste of time due to a large number of websites ignoring the existence of QUIC. Thus, two independent helpers may inform the client about its availability. An Alt-Svc
response header may be used to specify the port QUIC is listening on, but requires an initial TCP / TLS connection to the website. A measurement
documented by Geoff Hutson from APNIC (as of June 2025) shows a clear sign of the Chrome browser relying on this method, performing a QUIC connection only on the second attempt (after the header was observed). Safari, on the other hand, queries for
HTTPS DNS record of the target domain to check for "h3" ALPN support. This record comes with lots of useful information (IPv4 and IPv6 hints, ECH and supported ALPNs) and improves the "time-to-QUIC", as it does not require a preceding TCP connection to the website.
As mentioned, QUIC also makes DPI-based per-domain access lists more difficult, as the protocol does not carry SNI in plaintext, contrary to TLS (without ECH extension). However, this does not stop certain
country-scale firewalls from using packet decryption, as all necessary encryption parameters are present in the handshake, unfortunately. This process comes at the expense of compute resources, as such the protocol may be completely
blocked in some cases.
In my opinion, the protocol has lots of potential for improving the overall user experience in the "World Wide Web". Apart from the examples with HTTP/3 it has also found its use with DNS, both as an underlay (DoQ) and overlay (spoiler alert), which additionally improve the privacy and availability of the resources.
#http #quic #networking #dpi #firewall