Re: h2#373 HPACK attack mitigation options


On Mar 5, 2014, at 7:22 AM, Roberto Peon <> wrote:
> The issue isn't the reference set in this case, rather it is that the originator of the request != the destination for the request, which allows the originator to probe the compressor dynamic state-table.
> If options 1 or 4 are taken, then grouping or some similar signaling may need to be reintroduced. Opening an outgoing connection for each incoming connection is not the greatest thing in the world as it defeats several of the nice properties of HTTP/2.

FWIW, it wouldn't be the end of the world as you are still reducing the connection load from N connections per client to 1 per client - probably an order of magnitude difference with today's browsers.

Michael Sweet, Senior Printing System Engineer, PWG Chair

Received on Wednesday, 5 March 2014 13:13:16 UTC