Re: [Openvpn-devel] Discussion: Moving forward with compression and voracle

2018-08-24 Thread Gert Doering
Hi, On Fri, Aug 24, 2018 at 04:31:44PM +0200, David Sommerseth wrote: > > Open Points: > > > > - Gert strongly thinks that some people might want to continue having > > full compression despite the risks. I think it is reasonable to expect > > them to add 'compress-direction full' and push "compr

Re: [Openvpn-devel] Discussion: Moving forward with compression and voracle

2018-08-24 Thread David Sommerseth
On 24/08/18 13:11, Arne Schwabe wrote: > Hey, [...snip...] > - Introduce compress-direction asym|full This will control if we > actively try to compress or just allow receiving of compressed packets I'm not sold on this one at all. > - change the default mode to be asymmetrical. Agreed. Local s

Re: [Openvpn-devel] Discussion: Moving forward with compression and voracle

2018-08-24 Thread tincanteksup
On 24/08/18 12:11, Arne Schwabe wrote: Hey, with this mail I would like to discuss the way forward for compression. Our default configuration has not compression enabled. So our default configuration is safe from Voracle. I would like to have some feedback what the rest of you t

Re: [Openvpn-devel] Discussion: Moving forward with compression and voracle

2018-08-24 Thread Gert Doering
Hi, On Fri, Aug 24, 2018 at 01:11:44PM +0200, Arne Schwabe wrote: > On top of that, a lot of the traffic that the VPN carry today is either > already compressed or encrypted and cannot be compressed any more. So > benefits are diminishing. This part is true for the "I use a VPN to safely surf the

[Openvpn-devel] Discussion: Moving forward with compression and voracle

2018-08-24 Thread Arne Schwabe
Hey, with this mail I would like to discuss the way forward for compression. When compression was added to OpenVPN, a lot of Internet traffic was still unencrypted and encryption+compression was thought to be good thing. With recent attack like CRIME, BEAST and VORACLE, the general consensus in t