Re: Patch to minimize session fixation (continued)

From: Date: Wed, 07 Apr 2004 20:52:10 +0000
Subject: Re: Patch to minimize session fixation (continued)
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-8972@lists.php.net to get a copy of this message
On Wed, 7 Apr 2004, Chris Shiflett wrote: > --- Christian Schneider <cschneid@cschneid.com> wrote: > > I decided to say "If X knows the session ID of User A then he _is_ A". > > This isn't a good approach, but you can bring this up on php-general to > discuss why. I'm sure plenty of people will be happy to discuss it. > > > (Side note: I use my own random/MD5-based session IDs which should be > > hard to guess). PHP's generated from remote ID, process id, time and some randomness; and then MD5'ed. That's 'better' then your random/MD5 based approach as it's even less likely to result in collisions. regards, Derick

« previous php.internals (#8972) next »