Igeometry Podcast
How HTTP Compression Leaks Sessions and JWT - CRIME Explained and how HPACK in HTTP/2 fixes this
- Author: Vários
- Narrator: Vários
- Publisher: Podcast
- Duration: 0:21:05
- More information
Informações:
Synopsis
In this video we will explore one of the most popular side attacks CRIME Compression Ratio Info-leak Made Easy) and the different ways to mitigate this. Intro 0:00 * HTTP/1.1 SPDY header compression 4:00* TLS compression * Response body attackers can’t inject 13:00 * Mitigations 14:10 * HPACK/QPACK * TLS Padding --- Support this podcast: https://anchor.fm/hnasr/support