[Standards-JIG] NEW: JEP-0170 (Recommended Order of Stream Feature Negotiation)
stpeter at jabber.org
Wed Jan 11 19:55:06 UTC 2006
Jesus Cea wrote:
> Since compression can add a lot of overhead to the server, especially
> memory, I would rather suggest to first autenticate and then negociate
> compression. I imagine a trivial attact: simply open a lot of
> connections to a jabber server, negociate compression and go to sleep.
> Each connection can eat easily 500 Kbytes. 1000 connections eats 500
Good point. In fact the server probably should not even advertise the
compression feature until after authentication...
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 3641 bytes
Desc: S/MIME Cryptographic Signature
More information about the Standards