Re: Re: Crypt salts not random.. (fwd)
| From: | John Donagher | Date: | Sun, 29 Apr 2001 14:22:23 +0000 |
| Subject: | Re: Re: Crypt salts not random.. (fwd) | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-52971@lists.php.net to get a copy of this message | ||
On Sun, 29 Apr 2001, Zeev Suraski wrote:
> In order to avoid this you actually have to call it at completely different
> times, something you can't really guarantee. We should probably not use
> the timestamp as the seed (at least not alone), but also take the pid into
> account.
>
> Zeev
>
That only really works for forking webservers, does it not? Another alternative
would be to use microseconds...
--
John Donagher
Application Engineer
Intacct Corp. - Powerful Accounting on the Web
408-395-0989
720 University Ave.
Los Gatos CA 95032
www.intacct.com
Public key available off http://www.keyserver.net
Key fingerprint = 4024 DF50 56EE 19A3 258A D628 22DE AD56 EEBE 8DDD