> Why is this necessary? Shouldn't all encrypted traffic be
> compressed to begin with?
Compressing and then encrypting is dangerous in a partially chosen plaintext environment like HTTPS (and Nokia is probably putting their customers at risk by doing it).
The threat is as follows:
Threat model: Alice is a user on bob.com. Alice also occasionally visits HTTP websites. Eve wants to obtain Alice's bob.com cookie to gain unauthorised access to bob.com. Eve has full access to the network connection between Alice and Bob.com, and can add, delete, or modify packets as desired.
Browser software: HTTPS requests modelled as encrypt(gzip(knownText1 + queryParameters + knownText2 + secretCookie + knownText3)). By injecting a Javascript file controlled by Eve into a normal HTTP transaction, Eve can initiate HTTPS requests to bob.com using XMLHttpRequest where Eve knows the content of knownText* and fully controls the content of queryParameters.
If queryParameters contains a substring also found in secretCookie, then the overall length of the ciphertext will be shorter due to the fact that repeated substrings are compressed. When Eve confirms an initial substring of secretCookie by monitoring the length of ciphertext corresponding to a chosen queryParameters, Eve can then expand that substring in queryParameters iteratively to a longer substring until Eve has determined the entire value of secretCookie, completing the attack.