559
        
            
                I use Zip Bombs to Protect my Server
 
            
            (idiallo.com)
          
          
          
          
          
        This is a most excellent place for technology news and articles.
Brotli gets it to 8.3K, and is supported in most browsers, so there's a chance scrapers also support it.
Gzip encoding has been part of the HTTP protocol for a long time and every server-side HTTP library out there supports it, and phishing/scrapper bots will be done with server-side libraries, not using browser engines.
~~Further, judging by the guy's example in his article he's not using gzip with maximum compression when generating the zip bomb files: he needs to add -9 to the gzip command line to get the best compression (but it will be slower).~~ (I tested this and it made no difference at all).
You can make multiple files with different encodings and select based on the
Accept-Encodingheader.Yeah, good point.
I forgot about that.