Re: Re: [RFC][DISCUSSION] Session ID without hashing
| From: | Stanislav Malyshev | Date: | Wed, 29 Jun 2016 00:09:54 +0000 |
| Subject: | Re: Re: [RFC][DISCUSSION] Session ID without hashing | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-94319@lists.php.net to get a copy of this message | ||
Hi!
> Concern has been discussed is risk of broken PRNG and predictable
> session ID. We may insist any platform must have reliable PRNG, but it
> would be good idea to have least mitigation. Reading extra bytes
> should be good enough for this purpose.
I still see no reason to change it stated in the RFC except performance
(which is irrelevant in all contexts I know of). It states the change
but omits the reason why this change is necessary. Could you please add
that part?
--
Stas Malyshev
smalyshev@gmail.com