Changes between Initial Version and Version 1 of Ticket #1977


Ignore:
Timestamp:
05/14/20 00:58:44 (5 years ago)
Author:
Craig Andrews
Comment:

Legend:

Unmodified
Added
Removed
Modified
  • Ticket #1977 – Description

    initial v1  
    11The TLS specification (RFC 8446) section 5.4 defines optional Record Padding: https://tools.ietf.org/html/rfc8446#section-5.4
    22
    3 As a security improvement, I suggest that httpd implement random record padding.
     3As a security improvement, I suggest that nginx implement random record padding.
    44
    55Random record padding would mitigate the BREACH attack (and other similar) vulnerabilities.