Beast / CRIME / Beach attack and stopping it

Posted by user2143356 on Server Fault See other posts from Server Fault or by user2143356
Published on 2013-10-18T14:25:35Z Indexed on 2013/10/18 15:57 UTC
Read the original article Hit count: 222

Filed under:
|
|
|

I have read so much on all this but not entirely sure I understand what has gone on.

Also, is this one, two or three problems?

It looks to me like three, but it's all very confusing:

Beast
CRIME
Beach

It seems the solution may be to simply not use compression with HTTPS traffic (or is that just on one of them?)

I use GZIP compression. Is that okay, or is that part of the problem?

I also use Ubuntu 12.04 LTS

Also, is non-HTTPS traffic okay?

So after reading all the theory I just want the solution. I think this may be the solution, but can someone please confirm I have understood everything so I am not likely to suffer from this attack:

SOLUTION: Use GZIP compression on HTTP traffic, but don't use any compression on HTTPS traffic

© Server Fault or respective owner

Related posts about apache2

Related posts about ubuntu