By the way – SSL & security

Those who looks at my webserver very carefully will probably notice that i have disabled any compression. The reason for this is the use of SSL for SPDY and this: plus this:

SSL with compression has the risk that an attacker may decrypt the transferred data much easier. The only solution to this is to avoid any compression.

Just to make it clear: SPDY indeed builds on SSL – but the problem is SSL and the reduction of the transferred data by using compression. Without compression SSL and SPDY can be used safely.

Update 2012-10-31: Compressing the content is not that problematic, since the information which is interesting for an attacker, like session cookies, are transferred in the header which will not be compressed even with active compression of the content. Maybe you have to make sure, that the configuration of mod_ssl in Apache contains the option SSLCompression off. Therefore i decided to enable content compression again and just leave SSL compression disabled (also see the test at

Leave a public comment

Your email address will not be published. This is not a contact form! If you want to send me a personal message, use my e-mail address in the imprint.

You can use the following HTML tags in the comment:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>