Re: [RFC][VOTE] Session ID without hashing

From: Date: Mon, 04 Jul 2016 22:23:42 +0000
Subject: Re: [RFC][VOTE] Session ID without hashing
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-94376@lists.php.net to get a copy of this message
Hi! > Could you share the reason why against this change? 1. I'm not sure exporting raw generator state is a good practice. I may change my opinion on the subject if I hear from some security people (I'm no crypto expert) that this is ok, then I may change my opinion. 2. Due to (1), I do not think it makes sense to do this change, because we produce no benefit (session generation speed is not that important since nobody generates millions of sessions at once) and create potential problems. -- Stas Malyshev smalyshev@gmail.com

« previous php.internals (#94376) next »