Open
Description
According to this thread, compression can be vulnerable to CRIME/BREACH attacks (if the encrypted data carries public data as well).
I am not into crypto but I guess compression should be opt-in, at least, shouldn't it?
(This issue was migrated here from dev-sec/ansible-ssh-hardening#90)