From: Evgeny Kotkov Some web applications are vulnerable to an information disclosure
- attack when a TLS connection carries deflate compressed data. For more
+ attack when a TLS connection carries compressed data. For more
information, review the details of the "BREACH" family of attacks. This is a simple configuration that compresses common text-based content types. Some web applications are vulnerable to an information disclosure
- attack when a TLS connection carries deflate compressed data. For more
+ attack when a TLS connection carries compressed data. For more
information, review the details of the "BREACH" family of attacks.User-Agent
header, you must
manually configure an addition to the Vary
header
to alert proxies of the additional restrictions. For example,
- in a typical configuration where the addition of the DEFLATE
+ in a typical configuration where the addition of the BROTLI_COMPRESS
filter depends on the User-Agent
, you should add: