Comment on Revisiting the “Cookieless Domain” RecommendationparentComments−elchief11yHTTP compression is simply not safe on your main web domain: http://security.stackexchange.com/questions/20406/is-http-co...What I was trying to say is that, if you're security conscious, and running a CDN anyway, it might not be worth the risk to allow (selective) HTTP compression on your main web domain. It would be safer to disable it completely.
Comments
HTTP compression is simply not safe on your main web domain: http://security.stackexchange.com/questions/20406/is-http-co...
What I was trying to say is that, if you're security conscious, and running a CDN anyway, it might not be worth the risk to allow (selective) HTTP compression on your main web domain. It would be safer to disable it completely.