Trending Topics

Every technological cure has a side effect
This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.
From the architecture of the internet to encryption, cloud computing and HTTP/3, every breakthrough solves real problems while creating new ones for somebody else to manage
Medicine offers a useful lesson about progress. A new treatment can cure one condition while introducing side effects somewhere else. Antibiotics transformed modern healthcare, but their success also created the conditions for antimicrobial resistance. The conclusion is not that antibiotics were a mistake. It is that solving one problem changes the system around it, and the changed system creates new problems of its own.
Technology works much the same way. We like to describe progress as a straight line: networks become faster, cloud platforms more scalable, encryption stronger and AI more capable. Each generation fixes something that frustrated the generation before it. Yet progress rarely removes risk altogether. More often, it shifts risk elsewhere, changes its form, or exposes weaknesses that did not previously matter.
That does not make progress bad. It simply means that every improvement changes the assumptions on which the rest of the system was built, and those assumptions rarely change everywhere at the same time. Old and new technologies coexist, sometimes for decades, and it is often in that overlap that unexpected security problems emerge.
A recent piece of research into an attack called CDN Tsunami is a good example.
When efficiency creates a weakness
HTTP/3 was created to improve how the web works. Built on QUIC rather than TCP, it reduces connection overhead, handles packet loss better across concurrent streams and is particularly useful across mobile and less reliable networks. It also uses QPACK to compress HTTP headers more efficiently. These are genuine improvements, and HTTP/3 is now supported on roughly 40% of web requests measured by HTTP Archive.
The problem is that the internet does not upgrade all at once. A browser may speak HTTP/3 to a CDN while the CDN continues speaking HTTP/1.1 to the origin server behind it. This is a perfectly normal architecture, and often a practical one, because it allows the edge of the internet to adopt newer protocols without forcing every application server, firewall and load balancer to upgrade simultaneously.
CDN Tsunami shows what can happen in that transition. Researchers demonstrated that a compact, efficiently compressed HTTP/3 request can expand significantly when the CDN translates it into HTTP/1.1 for the origin. They also showed that multiple HTTP/3 streams carried efficiently within a QUIC connection can translate into disproportionate backend connection usage. Under specific experimental conditions, the reported bandwidth amplification reached approximately 350 times.
The important point is that none of the individual technologies needs to be broken. QPACK can be compressing headers exactly as designed, QUIC can be multiplexing streams exactly as designed, and HTTP/1.1 can be receiving ordinary HTTP exactly as designed. The weakness appears in the relationship between those components, when the efficiency of one side is converted into much greater resource consumption on the other.
The internet has always carried the side effects of its own success
DDoS itself follows the same pattern. One of the internet’s defining achievements is that millions of independently operated devices and networks can communicate with one another. Its openness, interoperability and decentralisation are precisely what allowed it to become global, but those same characteristics also make distributed attacks possible.
If millions of legitimate machines can communicate with the same service, then millions of compromised machines can do the same thing. Reflection attacks exploit protocols that were designed to respond to requests. Botnets exploit cheap and ubiquitous connectivity. Application-layer attacks exploit the fact that a small request can sometimes make a server perform substantial work.
This is one reason DDoS is unlikely to simply disappear through some final technical fix. Many DDoS techniques are abuses of capabilities the internet genuinely needs. We could imagine a network in which every communication path was tightly controlled, every identity centrally verified and every request pre-authorised, but it would no longer resemble the open internet that became successful in the first place.
The problem is not simply that the internet was badly designed. It was designed for a different environment, with different assumptions and priorities. Progress changed the environment, and attackers learned to exploit the gap between those original assumptions and present-day reality.
Encryption gave us protection — and attackers learned to weaponise it
Encryption may be an even clearer example of technology becoming double-edged. We spent decades improving cryptography precisely because we wanted encryption to be difficult, ideally impossible, to break without the correct key. Strong encryption protects banking, government communications, personal messages, intellectual property and almost every meaningful digital transaction.
Ransomware turns that success against us. Attackers do not need to defeat strong encryption; they use it. The same mathematical property that prevents an unauthorised person from reading protected data can be used to prevent the rightful owner from accessing their own files. In that sense, one of cybersecurity’s greatest defensive achievements became a highly effective offensive tool.
The answer, obviously, is not weaker encryption. We still need encryption to be strong. Instead, the security problem moves elsewhere: toward endpoint protection, identity controls, privilege management, backups, recovery architecture and the ability to stop an attacker before they obtain the opportunity to encrypt valuable data.
That is the recurring pattern. The technology solves the problem it was designed to solve, while simultaneously changing where the next problem will appear.
Every new capability has an inverse use case
The same principle can be seen across much of modern technology. APIs make software easier to integrate and automate, but also allow attackers to interact with applications at machine speed. Automation lowers the cost of repetitive work for defenders and businesses, while lowering it for attackers too. AI makes analysis, writing and software development cheaper and faster, but can also reduce the cost of reconnaissance, impersonation and attack automation.
Caching reduces infrastructure workload, while introducing questions around cache poisoning and consistency. Identity federation makes it easier for people to access multiple systems, while making a compromised identity potentially more valuable. Even observability and telemetry, designed to give organisations more insight into their infrastructure, can become sensitive sources of information if exposed to the wrong party.
The common thread is not that new technology is insecure. It is that every capability changes the economics and assumptions of the system around it.
Security teams therefore need to ask a second question whenever we celebrate an improvement. The first question is obvious: what can this technology now do? The second is less comfortable: what new asymmetry did we just create?
The real problem is often the transition
Perhaps the most interesting thing about CDN Tsunami is not HTTP/3 itself but the coexistence of technological generations. Technology rarely evolves by cleanly replacing one system with another. In practice, we end up with a new system connected to an old system through a translation layer, compatibility requirement or legacy dependency.
HTTP/3 clients coexist with HTTP/1.1 origins. Cloud-native applications depend on legacy identity systems. Modern APIs sit in front of databases designed decades ago. AI agents are beginning to interact with systems built on the assumption that every request originates from a human-operated application. Each generation adds another layer rather than completely removing the previous one.
These interfaces deserve more security attention than they often receive. Compatibility layers, gateways, protocol translators and proxies exist to make different generations of technology understand one another, but they also translate cost, state and resource consumption from one side to the other. That is precisely where asymmetry can appear.
CDN Tsunami makes the point vividly because the attacker does not necessarily need to generate enormous amounts of traffic directly. The attacker needs to find a situation in which a small amount of activity causes an intermediary to perform much more work downstream.
Once we look at security this way, amplification becomes a much broader concept than bandwidth. It can mean CPU time, memory, cloud spending, database queries, application workers, connection tables or even human attention. Any system where inexpensive input can trigger disproportionately expensive output creates an opportunity worth examining.
Progress needs custodians
None of this is an argument for slowing down technology. HTTP/3 should continue improving the internet. Cloud infrastructure should become more elastic. Encryption should become stronger. AI should become more capable. Progress is still progress, even when it creates new problems.
But if we accept that progress inevitably creates side effects, innovation cannot be the responsibility of builders alone. Medicine does not stop at discovering a new treatment. Clinicians, pharmacologists, researchers, regulators and public-health systems exist to understand what happens after that treatment enters the real world, including its side effects, interactions and unintended consequences.
Technology needs its own equivalent. Standards bodies, security researchers, infrastructure operators, cybersecurity professionals and technology providers all have a role to play in understanding what changed, identifying the weaknesses that emerged with it and building the safeguards that allow everyone else to keep moving forward.
This role becomes more important as systems become more complex, because complexity rarely disappears; it accumulates. Every new layer sits on top of something older, and every connection between them creates another place where assumptions can diverge. We therefore need people and organisations whose purpose is not simply to invent the next capability, but to continuously examine what that capability changes around it.
Progress does not remove risk. It redistributes it.
The task is not to avoid that reality, but to make sure someone is paying attention to where the risk went. Innovators will continue to push the frontier forward; the equally important job of technology’s custodians is to make sure that frontier remains habitable.
