Re: h2#373 HPACK attack mitigation options

Yup. "One can think of it as a variant of #1."
-=R


On Wed, Mar 5, 2014 at 3:29 AM, Martin Thomson <martin.thomson@gmail.com>wrote:

> On 5 March 2014 11:09, Roberto Peon <grmocg@gmail.com> wrote:
> > Option #4
> > Requests originating from a domain which is not the origin to which the
> > request is ultimately directed are disallowed to use *any* dynamic
> > compressor state.
>
> That would be a strict subset of #1 and thus perfectly good.
>

Received on Wednesday, 5 March 2014 11:43:34 UTC