Re: Re: Security changes in PHP 7
| From: | Tom Worster | Date: | Sun, 08 Feb 2015 19:18:32 +0000 |
| Subject: | Re: Re: Security changes in PHP 7 | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-82160@lists.php.net to get a copy of this message | ||
On 2/8/15, 12:52 PM, "Daniel Lowrey" <rdlowrey@php.net> wrote:
>On Sun, Feb 8, 2015 at 12:11 PM, Tom Worster <fsb@thefsb.org> wrote:
>>
>> Thanks Damien and Daniel for the info.
>>
>> I am not concerned about running out of entropy. I am concerned about
>> userspace RNGs such as OpenSSL
>>
>> http://sockpuppet.org/blog/2014/02/25/safely-generate-random-numbers/
>
>Just to be clear (as Damien also mentioned): openssl is not a userspace
>RNG.
OpenSSL has an RNG that is not in the kernel memory space. Software that
is
in memory but not in the kernel space is in the user space.