How HTTP Compression Leaks Sessions and JWT - CRIME Explained and how HPACK in HTTP/2 fixes this

The Backend Engineering Show with Hussein Nasser

Episode | Podcast

Date: Fri, 19 Mar 2021 20:57:22 GMT

<p>In this video we will explore one of the most popular side attacks CRIME Compression Ratio Info-leak Made Easy) and the different ways to mitigate this. &nbsp;&nbsp;Intro 0:00 &nbsp;* HTTP/1.1 SPDY header compression 4:00* TLS compression &nbsp;* Response body attackers can’t inject 13:00 &nbsp;* Mitigations &nbsp;14:10 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;* HPACK/QPACK &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;* TLS Padding</p>