Skip to content
This repository has been archived by the owner on Dec 26, 2020. It is now read-only.

Should compression be opt-in? #90

Closed
lpirl opened this issue Jan 21, 2017 · 2 comments
Closed

Should compression be opt-in? #90

lpirl opened this issue Jan 21, 2017 · 2 comments

Comments

@lpirl
Copy link

lpirl commented Jan 21, 2017

According to this thread, compression can be vulnerable to CRIME/BREACH attacks (if the encrypted data carries public data as well).

I am not into crypto but I guess compression should be opt-in, at least, shouldn't it?

@rndmh3ro
Copy link
Member

Hi @lpirl, could you please open this issue in the ssh-baseline repository? The settings made in this role are derived from the tests there and this question is much better placed there.

@lpirl
Copy link
Author

lpirl commented Jan 23, 2017

Thanks for the hint @rndmh3ro.
This is now dev-sec/ssh-baseline#78

@lpirl lpirl closed this as completed Jan 23, 2017
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants