Re: Early feedback on encrypted session PR
| From: | Craig Francis | Date: | Wed, 18 May 2022 16:37:52 +0000 |
| Subject: | Re: Early feedback on encrypted session PR | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-117744@lists.php.net to get a copy of this message | ||
On 18 May 2022, at 17:02, Mark Randall <marandall@php.net> wrote:
> Personally I usually just throw the session key through a one-way hash so the original session
> ID never gets written to a backing store.
Good idea, but that's not done by default.
> I'm not sure why reversible encryption needs to take place?
It might provide privacy (if the attacker can read the session files, and they contain sensitive
information, e.g. some developers store a copy of the users entire record in the session to avoid db
lookups)... and it might prevent edits being made to the session file.
I would hope both are very rare, but I'm still writing up reports about developers doing things
like
file_put_contents('/tmp/' . $_POST['id'],
$_POST['message']), so I don't have a lot of hope.
Craig