Re: JSON HASHDOS

From: Date: Wed, 24 Dec 2014 09:46:41 +0000
Subject: Re: JSON HASHDOS
References: 1 2 3 4 5 6 7  Groups: php.internals 
Request: Send a blank email to internals+get-79917@lists.php.net to get a copy of this message
Hi, On Wed, Dec 24, 2014 at 6:29 PM, Pierre Joye <pierre.php@gmail.com> wrote: > I do not see how it solves the problem. It only reduces it, slightly. > Having a couple of medium instances generating crafted requests will > just have the same effect. So far the more realistic suggestions are > about having collision safe implementation, not implementation with > limited collisions. > It's ideal, but other languages are just switched to more secure hash and random seed. I'm not sure how feasible it would be. > > > P.S. Did we decide to have 64 bit array keys? 64 bit array key is much > more > > stronger against collisions. > > I would not say "much stronger", slightly stronger, but as long as the > same implementation is used, it does not really solve anything on this > area. > If we use the same DJB hash algo, it would not change situation much. I agree. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#79917) next »