Skip to content
This repository was archived by the owner on Dec 26, 2020. It is now read-only.

Should compression be opt-in? #90

Closed
lpirl opened this issue Jan 21, 2017 · 2 comments
Closed

Should compression be opt-in? #90

lpirl opened this issue Jan 21, 2017 · 2 comments

Comments

@lpirl
Copy link

lpirl commented Jan 21, 2017

According to this thread, compression can be vulnerable to CRIME/BREACH attacks (if the encrypted data carries public data as well).

I am not into crypto but I guess compression should be opt-in, at least, shouldn't it?

@rndmh3ro
Copy link
Member

Hi @lpirl, could you please open this issue in the ssh-baseline repository? The settings made in this role are derived from the tests there and this question is much better placed there.

@lpirl
Copy link
Author

lpirl commented Jan 23, 2017

Thanks for the hint @rndmh3ro.
This is now dev-sec/ssh-baseline#78

@lpirl lpirl closed this as completed Jan 23, 2017
# for free to subscribe to this conversation on GitHub. Already have an account? #.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants