Re: Re: [RFC][VOTE] Session ID without hashing

From: Date: Tue, 05 Jul 2016 20:35:26 +0000
Subject: Re: Re: [RFC][VOTE] Session ID without hashing
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-94393@lists.php.net to get a copy of this message
Hi! > Some of us worried about CSPRNG state exposure. I'm wondering how many > of you will vote in favor if I change the RFC to use hash functions > optionally. This means code and INI settings related to hash function > selection will remain. Please note that ext/hash is not built always. > If you against keeping hash related code, please let me know also. If there would be an option to not use hash, I would be completely fine with it. -- Stas Malyshev smalyshev@gmail.com

« previous php.internals (#94393) next »