Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Always support compressed response in an API service (ashishb.net)
2 points by todsacerdoti 10 months ago | hide | past | favorite | 1 comment


Please note that BREACH[0] is still a thing, and you probably don't want to compress api responses without thinking about mitigating against this class of attacks.

[0]: https://en.wikipedia.org/wiki/BREACH




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: