Do recent SSL issues like 'BREACH' effect OpenVPN?
Posted: Mon Aug 05, 2013 7:11 pm
Hi,
I was just wondering if anyone out there was familiar with some of the recent SSL vulnerabilities (i.e. BREACH), and could comment if they might theoretically apply to OpenVPN's use of SSL. If they do, is there an easy way to mitigate this issue? From what I've read the problem has to do with how some data is compressed for transmission. So, would turning off OpenVPN's compression mitigate any potential risk?
I confess I don't know enough to even pretend to speak intelligently on this subject, but I'm hoping someone else out there does.
Thanks!
I was just wondering if anyone out there was familiar with some of the recent SSL vulnerabilities (i.e. BREACH), and could comment if they might theoretically apply to OpenVPN's use of SSL. If they do, is there an easy way to mitigate this issue? From what I've read the problem has to do with how some data is compressed for transmission. So, would turning off OpenVPN's compression mitigate any potential risk?
I confess I don't know enough to even pretend to speak intelligently on this subject, but I'm hoping someone else out there does.
Thanks!