Re: Re: [RFC][VOTE] Session ID without hashing
| From: | Stanislav Malyshev | Date: | Tue, 05 Jul 2016 20:35:26 +0000 |
| Subject: | Re: Re: [RFC][VOTE] Session ID without hashing | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-94393@lists.php.net to get a copy of this message | ||
Hi!
> Some of us worried about CSPRNG state exposure. I'm wondering how many
> of you will vote in favor if I change the RFC to use hash functions
> optionally. This means code and INI settings related to hash function
> selection will remain. Please note that ext/hash is not built always.
> If you against keeping hash related code, please let me know also.
If there would be an option to not use hash, I would be completely fine
with it.
--
Stas Malyshev
smalyshev@gmail.com