SSL is now vulnerable to session hijacking in some circumstances. If your site runs SSL/TLS, the compression needs to be off.
http://security.stackexchange.com/questions/19911/crime-how-to-beat-the-beast-successor/19914#19914
Thoughts on tech and random things I find on the web
SSL is now vulnerable to session hijacking in some circumstances. If your site runs SSL/TLS, the compression needs to be off.
http://security.stackexchange.com/questions/19911/crime-how-to-beat-the-beast-successor/19914#19914
Recent Comments