From: | "Michael J(dot) Baars" <mjbaars1977(dot)pgsql(dot)hackers(at)gmail(dot)com> |
---|---|
To: | pgsql-hackers(at)lists(dot)postgresql(dot)org |
Cc: | Abhijit Menon-Sen <ams(at)toroid(dot)org> |
Subject: | Re: SSL compression |
Date: | 2021-11-08 09:10:55 |
Message-ID: | af63d73caaa6ef82f46a86205826a70bd689e73b.camel@gmail.com |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-hackers |
On Mon, 2021-11-08 at 13:30 +0530, Abhijit Menon-Sen wrote:
> At 2021-11-08 08:41:42 +0100, mjbaars1977(dot)pgsql(dot)hackers(at)gmail(dot)com wrote:
> > Could someone please explain to me, why compression is being
> > considered unsafe / insecure?
>
> https://en.wikipedia.org/wiki/CRIME
>
Well Abhijit, personally I don't see any connection between crime and compression. I do see however, that some people might feel safer communicating over an SSL
ENCRYPTED line doing their daily business, unjustified as that is, but they shouldn't be feeling safer communicating over a compressed line, that would be
utterly stupid.
The sole purpose of compression is to reduce the size of a particular amount of data.
> > Might the underlying reason be, that certain people have shown
> > interest in my libpq/PQblockwrite algorithms (
> > https://www.postgresql.org/message-id/c7cccd0777f39c53b9514e3824badf276759fa87.camel%40cyberfiber.eu)
> > but felt turned down and are now persuading me to trade the algorithms
> > against SSL compression, than just say so please. I'll see what I can
> > do.
>
> The whole world is trying to move away from TLS compression (which has
> been removed from TLS 1.3). It has nothing to do with you.
As I understand it, TLS is a predecessor of SSL. People are trying to move away from TLS, not from compression.
>
> -- Abhijit
From | Date | Subject | |
---|---|---|---|
Next Message | Magnus Hagander | 2021-11-08 09:20:33 | Re: SSL compression |
Previous Message | Dinesh Chemuduru | 2021-11-08 08:56:59 | Re: [PROPOSAL] new diagnostic items for the dynamic sql |