Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Should the following text be formatted using <aside>? (comment 7) #4973

Closed
LPardue opened this issue Mar 25, 2022 · 2 comments
Closed

Should the following text be formatted using <aside>? (comment 7) #4973

LPardue opened this issue Mar 25, 2022 · 2 comments
Labels

Comments

@LPardue
Copy link
Member

@LPardue LPardue commented Mar 25, 2022

Should the following text be formatted using

? See the definition at https://authors.ietf.org/rfcxml-vocabulary#aside.

Original:

   Note:  Padding schemes only provide limited protection against an
      attacker with these capabilities, potentially only forcing an
      increased number of guesses to learn the length associated with a
      given guess.  Padding schemes also work directly against
      compression by increasing the number of bits that are transmitted.

Original:

   Note:  Simply removing entries corresponding to the field from the
      dynamic table can be ineffectual if the attacker has a reliable
      way of causing values to be reinstalled.  For example, a request
      to load an image in a web browser typically includes the Cookie
      header field (a potentially highly valued target for this sort of
      attack), and websites can easily force an image to be loaded,
      thereby refreshing the entry in the dynamic table.
@MikeBishop
Copy link
Contributor

@MikeBishop MikeBishop commented Apr 1, 2022

Probably yes.

MikeBishop added a commit that referenced this issue Apr 26, 2022
@MikeBishop
Copy link
Contributor

@MikeBishop MikeBishop commented May 9, 2022

Fixed in #4986.

@MikeBishop MikeBishop closed this May 9, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants