[Cryptography] Is there a good algorithm providing both compression and encryption at the same time?
rsalz at akamai.com
Tue May 12 07:27:45 EDT 2015
>The argument goes that
> encryption will thwart the censors. Except of course that the encrypted
> traffic still reveal page lengths, compressed or not...
Which is why HTTP/2 has padding, and TLS 1.3 will probably have it.
The IETF isn't "encrypt everything" but rather "pervasive monitoring is an attack," with the knowledge that protection of meta-data (DNS, padding, timing) is important. There's no guarantee we'll get it right, or even if it's possible, but they're trying.
More information about the cryptography