Quantcast
Channel: Nginx Forum - Nginx Mailing List - English
Viewing all articles
Browse latest Browse all 7229

simple BREACH workaround for gzip (no replies)

$
0
0
Hello,
has anyone considered this simple workaround for BREACH and gzip-compression, i.e. randomly interspersed flush()-es during compression?
https://github.com/wnyc/breach_buster
It would be compatible with all clients, and should be fairly easy to implement in nginx (for nginx hackers).
Of course, it doesn't prevent BREACH attacks, but it makes them much harder.

PS: yes, I'm aware that BREACH should also be prevented in the app-layer,

Viewing all articles
Browse latest Browse all 7229

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>