RE: [PHP-DEV] Re: Crypt salts not random.. (fwd)
| From: | James Moore | Date: | Sun, 29 Apr 2001 19:00:45 +0000 |
| Subject: | RE: [PHP-DEV] Re: Crypt salts not random.. (fwd) | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-52973@lists.php.net to get a copy of this message | ||
> > > In order to avoid this you actually have to call it at completely
> > different
> > > times, something you can't really guarantee. We should
> probably not use
> > > the timestamp as the seed (at least not alone), but also take
> the pid into
> > > account.
> > >
> > > Zeev
> > >
> >
> >That only really works for forking webservers, does it not? Another
> >alternative
> >would be to use microseconds...
>
> Yeah we could use microseconds but are they available on all platforms?
> In any case, on non-forking servers we can use thread id.
We have accuracy to milliseconds only on Win32.
- James