Re: Request #65501 uniqid(): More entropy parameter should be true by default
| From: | Lars Strojny | Date: | Sat, 24 Aug 2013 10:30:53 +0000 |
| Subject: | Re: Request #65501 uniqid(): More entropy parameter should be true by default | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-68619@lists.php.net to get a copy of this message | ||
Hi Nikita,
Am 24.08.2013 um 12:08 schrieb Nikita Popov <nikita.ppv@gmail.com>:
[....]
> We already have a great (version 4) UUID implementation called
> mcrypt_create_iv, just minus the fixed sequences and fancy formatting.
> Apart from moving this to core (not requiring mcrypt/openssl) and maybe
> adding alphabet support, I don't immediately see why this wouldn't be
> sufficient. Why do we need fancy UUID formatting or "unique hashes"
> (whatever that is supposed to be...)?
mcrypt_create_iv() is great but it is about usability: not every user of the language can create a
UUIDs from mcrypt_create_iv() and we should make it as easy as possible to generate unique IDs. That
said, a simple uuid($version) function would not hurt the core. I would argue that this is very
similar to the password_hash() API. It was possible before the password API to store password
securely, but we made it way easier now, which is a very good thing.
cu,
Lars
Attachment: [application/pgp-signature] Message signed with OpenPGP using GPGMail signature.asc
Attachment: [application/pgp-signature] Message signed with OpenPGP using GPGMail signature.asc