3 ms·
I don't think so. Here's the snippet from the linked PDF[1]: > DEFLATE [2] (the basis for gzip) takes advantage of repeated strings to shrink the compressed pa
by sehrope 13y ago
I don't think so. Here's the snippet from the linked PDF[1]:
> DEFLATE [2] (the basis for gzip) takes advantage of repeated strings to shrink
the compressed payload, an attacker can use the the reflected URL parameter to
guess the secret one character at a time.
By encrypting the CSRF token (or any other "secret" data you want to roundtrip from server to client and back) with a random IV per request this wouldn't work. The value sent by the client would not be the same as the new token generated by the server (since each has a random IV). Even though the decrypted value of each token is the same, the values presented to the client in the response body are each different and not predictable (to the client).
[1]: http://breachattack.com/resources/BREACH%20-%20SSL,%20gone%20in%2030%20seconds.pdf http://breachattack.com/resources/BREACH%20-%20SSL,%20gone%2...