Re: [lists.php] Re: [PHP-DEV] [RFC] more secure unserialize()
| From: | ALeX | Date: | Sun, 31 Mar 2013 21:18:16 +0000 |
| Subject: | Re: [lists.php] Re: [PHP-DEV] [RFC] more secure unserialize() | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-66875@lists.php.net to get a copy of this message | ||
> JSON and serialize() are (inherently) different serialization formats with different use-cases
> [...]
Yes, and json requires that all strings (including the keys) has to be
valid utf-8, and I'm sure that's not always the case (serialize can
use binary data in both places).