Re: Session Id Collisions

From: Date: Mon, 05 Aug 2013 19:17:10 +0000
Subject: Re: Session Id Collisions
References: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20  Groups: php.internals 
Request: Send a blank email to internals+get-68388@lists.php.net to get a copy of this message
Hi Yasuo, On Mon, Aug 5, 2013 at 7:46 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > On Tue, Aug 6, 2013 at 1:04 AM, Arpad Ray <arraypad@gmail.com> wrote: > >> I think there really should be a vote. > > > This means you don't really understand the true risk of this vulnerability. > It allows permanent session ID fixation. This is CVE assigned > vulnerability. > Details are explained in the RFC and I don't want to explain fully in ML > again. > (We might discussed the details in security@php.net, but I think I wrote > enough info) > > Please refer to the RFC. > I do really understand the risk... I'm saying there should be a vote not on whether or not to fix it, but on how to fix it. Ideally we can figure out something we're all happy with and don't need to vote, but while we so evidently disagree, I think we do. I'm not going to repeat my arguments against the committed solution yet again, but I really think we need a better one. Arpad

« previous php.internals (#68388) next »