Subverting OpenSSL library function with Windows alternatives
| From: | Scott MacVicar | Date: | Tue, 19 Jul 2011 22:35:34 +0000 |
| Subject: | Subverting OpenSSL library function with Windows alternatives | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-54092@lists.php.net to get a copy of this message | ||
Just noticed a commit from Pierre last week http://svn.php.net/viewvc?view=revision&revision=313112
which changed OpenSSL to use a special Windows API call for gathering random data.
I've reverted this change so we can discuss this further.
I disagree with advertising a library function and changing it to use something else. Especially
when this is around random data / encryption. The OpenSSL library has been audited externally, if
there is a better alternative then this patch should go upstream rather than being hacked into PHP.
If we want to offer this as win32_random_data() then I'm also fine with that.
- Scott