Re: Re: [RFC][VOTE] Session ID without hashing
| From: | Tom Worster | Date: | Tue, 05 Jul 2016 17:00:01 +0000 |
| Subject: | Re: Re: [RFC][VOTE] Session ID without hashing | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-94392@lists.php.net to get a copy of this message | ||
On 7/5/16 11:37 AM, Christoph Becker wrote:
On 05.07.2016 at 16:32, Leigh wrote:I hope so. It's not safe to use sessions if PHP cannot get unpredictable randoms for session IDs. PHP should therefore error so that the sys op can be alerted and fix the problem. TomOn 5 July 2016 at 04:02, Pierre Joye <pierre.php@gmail.com> wrote:Would that imply that in this latter case sessions couldn't be used anymore?We can argue about the provided pnrng being CS but it is not php's job to decide.I think we need to drop the concerns about exposing "RNG state". A reminder of what php_random_bytes looks at (in order): * CryptGenRandom on Windows * arc4random_buf on modern BSD (where ChaCha20 is used) * Linux getrandom(2) syscall where available * /dev/urandom where available * Throws an exception if it cannot access one of the above