[Cryptography] Is there a good algorithm providing both compression and encryption at the same time?

Salz, Rich rsalz at akamai.com
Tue May 12 07:27:45 EDT 2015


>The argument goes that
> encryption will thwart the censors. Except of course that the encrypted
> traffic still reveal page lengths, compressed or not...

Which is why HTTP/2 has padding, and TLS 1.3 will probably have it.

The IETF isn't "encrypt everything" but rather "pervasive monitoring is an attack," with the knowledge that protection of meta-data (DNS, padding, timing) is important.  There's no guarantee we'll get it right, or even if it's possible, but they're trying.


More information about the cryptography mailing list