top | item 41551119

(no title)

patrickmeenan | 1 year ago

SDCH was removed when SPECTRE became a thing (CRIME/BREACH) because it was open to side-channel attacks.

Yes, it had other problems, not the least of which was that it would block the processing of a response while a client fetched the dictionary, but the side-channel attacks were what killed it.

The compression dictionary transport work addresses all of the known issues that we had with SDCH and we're cautiously optimistic that this will be around for a long time.

discuss

order

No comments yet.