3 ms·
Yeah, the more I think about this, the worse it is. It's certainly not as general as the original CRIME TLS exploit, but that almost makes it more insidious. T
by AnIrishDuck 13y ago
Yeah, the more I think about this, the worse it is. It's certainly not as general as the original CRIME TLS exploit, but that almost makes it more insidious.
The big problem is that there's no blanket solution to this like there was with the TLS break. Then you could just turn off TLS compression, which wasn't a huge deal. Now, turning off HTTP compression is a much bigger problem. You're going to take a huge performance hit. The alternative is auditing every route in your application to ensure that it won't leak attacker info into a response - a very daunting proposition.