05/20/2026

What Is the BREACH Attack? How It Works and How to Stop It

BREACH is a compression side-channel attack that can leak CSRF tokens and other secrets over HTTPS. Here is how the BREACH attack works, why padding is weak protection, and how to prevent it properly.

Read more →
05/17/2026

What Is Zstd? NGINX, Angie, History and Browser Support

Zstd is the fast compression format suddenly showing up in browsers, package managers, and modern web stacks. Here is what it is, where it came from, which browsers and web servers support it, and how to use it with NGINX and Angie today.

Read more →
05/16/2026

Zstd vs Brotli vs zlib-ng: The NGINX Compression Deep Dive

Zstd vs Brotli vs zlib-ng only makes sense once you separate browser encodings from compression engines. This deep dive covers support, CPU trade-offs, static vs dynamic compression, and the NGINX production patterns that actually work.

Read more →
05/13/2026

NGINX Brotli Compression: Install, Configure and Pre-Compress Static Assets

Brotli achieves 15-26% better compression than gzip on HTML, CSS, and JavaScript. This guide covers installing the NGINX Brotli module, configuring on-the-fly compression, pre-compressing static assets at level 11, and running Brotli alongside gzip.

Read more →
05/10/2026

zstd-nginx-module: What Broke, What We Fixed, and Why It Matters

The first audit found 22 issues, but the last two weeks of git history added 14 more issue-level fixes. This updated guide covers the full 36-issue fork-window story, the runtime and build bugs, and the CI tests now guarding the module.

Read more →