M
M
Max Bozhenov2017-07-18 11:16:47
Gzip
Max Bozhenov, 2017-07-18 11:16:47

Secure connection HTTPS + GZip compression =?

Good day!

Actually, the question is from the title. The nginx config says it's best not to use gzip if the site is using an https connection. But! If you do not use gzip , google speed test cuts the result by about 20 points, which is quite a lot... But despite this, google actively promotes that we should use a secure https connection ... How to be? How to make these two guys friends?

ps: Googling other projects with https connection, it turned out that site owners either don’t know about minimization and compression at all, or they have everything turned on, and https , andgzip ... and most sites don't even reach 80 points.

Answer the question

In order to leave comments, you need to log in

4 answer(s)
I
Igor Vorotnev, 2017-07-18
@max_bozhenov

gzip and https work together without problems, however this opens up several potential vulnerabilities. With the right and skillful configuration, taking into account these new attack vectors and their smart mitigation, it is possible and necessary to use gzip + https. But, since many users of the hollow do not give away what they do in their configs, this combination is not recommended by default. read, for example, here .

A
Alexander Aksentiev, 2017-07-18
@Sanasol

and most sites do not even reach 80 points.

because this assessment is extremely one-sided. And it has little to do with reality.
Especially when it says that you can reduce images and JS that are already minified.
I have not yet seen a single site that fits into the top ratings for this counter.
Even Google itself gives results at the bottom level there (now it really gives out a lot due to the fact that instead of the page , the captcha comes out xD).
Better to use wider tools like https://tools.pingdom.com/
More informative result.
first time I hear about it.
Google did not give anything except for a vulnerability from 2012, which has already been fixed a long time ago.
Other than that, I see no reason to do so.

P
Puma Thailand, 2017-07-18
@opium

turn gzip on and don't mess around

H
havemanyquestions, 2019-12-15
@havemanyquestions

I also asked this question, but as if none of the respondents understood what it was about.
https://security.stackexchange.com/questions/65625...
https://xakep.ru/2013/08/07/61037/
breachattack.com
The problem, apparently, remains. You can share, but you need to understand what and how to configure.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question