Beast / CRIME / Beach attack and stopping it
Posted
by
user2143356
on Server Fault
See other posts from Server Fault
or by user2143356
Published on 2013-10-18T14:25:35Z
Indexed on
2013/10/18
15:57 UTC
Read the original article
Hit count: 222
I have read so much on all this but not entirely sure I understand what has gone on.
Also, is this one, two or three problems?
It looks to me like three, but it's all very confusing:
Beast
CRIME
Beach
It seems the solution may be to simply not use compression with HTTPS traffic (or is that just on one of them?)
I use GZIP compression. Is that okay, or is that part of the problem?
I also use Ubuntu 12.04 LTS
Also, is non-HTTPS traffic okay?
So after reading all the theory I just want the solution. I think this may be the solution, but can someone please confirm I have understood everything so I am not likely to suffer from this attack:
SOLUTION: Use GZIP compression on HTTP traffic, but don't use any compression on HTTPS traffic
© Server Fault or respective owner