[RFC][VOTE] Session ID without hashing

From: Date: Sat, 02 Jul 2016 07:35:21 +0000
Subject: [RFC][VOTE] Session ID without hashing
Groups: php.internals 
Request: Send a blank email to internals+get-94356@lists.php.net to get a copy of this message
Hi all, Currently session module uses obsolete MD5 for session ID. With CSPRNG, hashing is redundant and needless. It adds hash module dependency and inefficient (There is no reason to use hash for CSPRNG generated bytes). This proposal cleans up session code by removing hash. https://wiki.php.net/rfc/session-id-without-hashing I set vote requires 2/3 support. Please describe the reason why when you against this RFC. Reasons are important for improvements! Thank you! -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#94356) next »