Re: Make mcrypt_create_iv() an alias and move the code into /ext/standard
| From: | Yasuo Ohgaki | Date: | Fri, 07 Feb 2014 10:30:56 +0000 |
| Subject: | Re: Make mcrypt_create_iv() an alias and move the code into /ext/standard | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72370@lists.php.net to get a copy of this message | ||
Hi Thomas,
On Fri, Feb 7, 2014 at 4:05 PM, Thomas Hruska <thruska@cubiclesoft.com>wrote:
> Moving the guts of this non-dependent function into the core would allow
> mcrypt_create_iv() to just become an alias. The new userland function
> could be located in /ext/standard/rand.c and have an uncreative name like
> rand_bytes().
There is new great PECL package.
http://pecl.php.net/package/crypto
I would like to see it as default for crypt related feature.
Anyway, we need default rundom_bytes() function in ext/standard. This is
mandatory for secure apps, but we have no default function. This should be
resolved.
Anyway, mcrypt_create_iv() is not optimum, yet. Here is possible
improvement.
https://github.com/yohgaki/php-src/compare/PHP-5.6-mcrypt_create_iv
It still requires random source and it does not support windows well,
though.
I'm about to adding new function which solves all of them like session
module.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net