Who’s not getting gzip?
stevesouders.com
stevesouders.com
Anti-virus software may try to minimize CPU operations by intercepting and altering requests so that web servers send back uncompressed content. But if the CPU is not the bottleneck, the software is not doing users any favors. Some popular antivirus programs interfere with compression. Users can check if their anti-virus software is interfering with compression by visiting the browser compression test page at Browserscope.org.
Serious? Anti-virus software that is doing that is acting almost like malware doing what the user didn't ask it to do. Does compression have any even minor security implications that would legitimize this? And anyone know which anti-virus does this?
The quote you gave said that anti-virus apps might do it to "minimize(sic) CPU operations" rather than for security reasons.
;0P>
(You can say that they can just compress the signatures, but that probably wont work for the more complex compression schemes, because they are not that predictable. Or maybe it can work, but it was considered too hard to code by the AV people.)
Imagine a data stream X that is compressed into another data stream Y. Imagine that a small portion of X is data stream x1 which is the portion of data used for a signature. That will get compressed into y1. Now lets define x2 as all the data in X that is not x1. Now if you are always guaranteed that the same x1 would get compressed into the same y1, then things would be easily predictable and you can just compare compressed signatures. But this is not the case. If x2 is different, then the same x1 can be compressed into a different string.
What's probably happening is virus scanners are taking the easy way out rather than implementing decompression algorithms in their scanning engines (it probably looks better on traditional benchmarks too)
On your second point I agree. I'll refrain from ranting about AV programs here, but suffice to say there hasn't been enough innovation in the field because AV companies are able to sell substandard products and still make good money.
The gzip format documentation is available here btw: http://www.gzip.org/zlib/rfc-gzip.html
As for the browser mods, he controlled to look at the difference holding browser version/OS steady, so the changes would be consistent inside the browser,version,os pairing. It was a rather scientific approach imo.
mod_gzip_item_include reqheader "User-agent: .*MSIE 6.0.*"
Mind you, this has not been tested, interacts badly with proxies, and is based on a pretty broken idea in the first place. On the other hand, almost every modern browser supports gzip, so it's not clear how much it would hurt.One of the slides has their code-ready Apache configuration for gzip.