Re: Re: [RFC][DISCUSSION] Session ID without hashing

From: Date: Wed, 29 Jun 2016 00:09:54 +0000
Subject: Re: Re: [RFC][DISCUSSION] Session ID without hashing
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-94319@lists.php.net to get a copy of this message
Hi! > Concern has been discussed is risk of broken PRNG and predictable > session ID. We may insist any platform must have reliable PRNG, but it > would be good idea to have least mitigation. Reading extra bytes > should be good enough for this purpose. I still see no reason to change it stated in the RFC except performance (which is irrelevant in all contexts I know of). It states the change but omits the reason why this change is necessary. Could you please add that part? -- Stas Malyshev smalyshev@gmail.com

« previous php.internals (#94319) next »