Re: Re: [RFC][VOTE] Session ID without hashing
| From: | Yasuo Ohgaki | Date: | Tue, 05 Jul 2016 03:30:51 +0000 |
| Subject: | Re: Re: [RFC][VOTE] Session ID without hashing | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-94382@lists.php.net to get a copy of this message | ||
Hi Pierre,
On Tue, Jul 5, 2016 at 12:02 PM, Pierre Joye <pierre.php@gmail.com> wrote:
>> Current implementation is regenerating random hash string by using
>>
>> - PID
>> - Time (Simple random function)
>> - CSPRNG when it is available
>
> For clarification, it is always available. Php requires a valid one to be
> built.
>
> We can argue about the provided pnrng being CS but it is not php's job to
> decide.
Thank you for clarification!
Modern systems that execute PHP should have CSPRNG always.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net