Re: [RFC][VOTE] Session ID without hashing
| From: | Stanislav Malyshev | Date: | Mon, 04 Jul 2016 22:23:42 +0000 |
| Subject: | Re: [RFC][VOTE] Session ID without hashing | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-94376@lists.php.net to get a copy of this message | ||
Hi!
> Could you share the reason why against this change?
1. I'm not sure exporting raw generator state is a good practice. I may
change my opinion on the subject if I hear from some security people
(I'm no crypto expert) that this is ok, then I may change my opinion.
2. Due to (1), I do not think it makes sense to do this change, because
we produce no benefit (session generation speed is not that important
since nobody generates millions of sessions at once) and create
potential problems.
--
Stas Malyshev
smalyshev@gmail.com