Re: Override session id creation and cookie creation?
| From: | derick@php.net | Date: | Mon, 18 Feb 2002 15:50:00 +0000 |
| Subject: | Re: Override session id creation and cookie creation? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-80154@lists.php.net to get a copy of this message | ||
On Mon, 18 Feb 2002 mlwmohawk@mohawksoft.com wrote:
> > We have the same problem with SRM, Sterling tried to fix it, but didn't
> > succeed in this yet. Sascha also added that it doesn't really matter
> > who creates the id, because MD5 is random enough anyways.
>
> MD5 is not random. The session code relies on the random number generator
I wrote 'random enough', that's something different than random.
> in the single machine. All random number generators have a period of
> randomness. Given any sufficiently used system, there is a likelyhood of a
> collision. Given [n] machines sharing sessions, this probability increases.
>
> The only "correct" way to accomplish uniqueness is to check for existence.
I know that, and BTW, PHP is not using plain MD5, but the combination of a
random seed and MD5. Did you calculate the possibility it could collide?
It would be interesting to know...
Derick