Source
Veteran OT User
I'd make an issue on github instead, but I've heard TFS on github is toxic, and I'd probably not be welcomed, so I'd rather not get involved there.
Of course OTLand is too, but I don't care because it doesn't affect my github account.
To the topic:
I just "heard about"/looked up myself that TFS has packet compression now, after I had a talk with the developer behind Rust OT/RyOT where he uses compression, and I looked it up to consider using compression myself.
However from my understanding compression + encryption is inherently insecure and vulnerable to CRIME, which is an old well known exploit now, so probably easy to pull off, allowing people to eavesdrop on the client-server communications, defeating the purpose of XTEA.
Thoughts?
Of course OTLand is too, but I don't care because it doesn't affect my github account.
To the topic:
I just "heard about"/looked up myself that TFS has packet compression now, after I had a talk with the developer behind Rust OT/RyOT where he uses compression, and I looked it up to consider using compression myself.
However from my understanding compression + encryption is inherently insecure and vulnerable to CRIME, which is an old well known exploit now, so probably easy to pull off, allowing people to eavesdrop on the client-server communications, defeating the purpose of XTEA.
Thoughts?