> (this is not possible with client-side JavaScript).

You are wrong, read about HEIST attack.

With a HEIST attack CRIME and BREACH are now cross sites attacks also.

Also didn’t get your clear point, in what kind you are arguing with me? :)

In CRIME attack you can attack body and headers, in BREACH only body. Did I said something et contra?

