Skip to content

Comment on CRIMEparent

Comments

If this is all you hate SPDY for, your hatred is misplaced. Most HTTPS connections in the wild will have compression turned on anyway.

As I said compression is not the only condition that needs to be met for this attack to work. The browser needs to make requests to other sites, automatically, e.g. via an img src tag.

As for HTTPS, nothing requires me to seek out sites that use HTTPS. Nor to trust sites that use it which I'm forced to use. And nothing requires me to send headers asking for compression support when using HTTP. But with SPDY, everything is compressed, all the time. It's all on by default. This is by design.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.