Re: [RFC][VOTE] Session ID without hashing
| From: | Yasuo Ohgaki | Date: | Fri, 08 Jul 2016 01:43:06 +0000 |
| Subject: | Re: [RFC][VOTE] Session ID without hashing | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-94427@lists.php.net to get a copy of this message | ||
Hi Derick,
On Thu, Jul 7, 2016 at 9:29 PM, Derick Rethans <derick@php.net> wrote:
>> Hi all,
>>
>> Currently session module uses obsolete MD5 for session ID. With
>> CSPRNG, hashing is redundant and needless. It adds hash module
>> dependency and inefficient (There is no reason to use hash for CSPRNG
>> generated bytes).
>>
>> This proposal cleans up session code by removing hash.
>>
>> https://wiki.php.net/rfc/session-id-without-hashing
>>
>> I set vote requires 2/3 support.
>> Please describe the reason why when you against this RFC. Reasons are
>> important for improvements!
>
> I'm voting "no" bceause of
>
> session.use_strict_mode (0 to 1) - Changed as insurance of broken PRNG implementation.
>
> And it not being mentioned in BC breaking changes. It changes behaviour
> of session IDs, as it shown in the manual:
>
> session.use_strict_mode boolean
>
> session.use_strict_mode specifies whether the module will use strict
> session id mode. If this mode is enabled, the module does not accept
> uninitialized session ID. If uninitialized session ID is sent from
> browser, new session ID is sent to browser. Applications are
> protected from session fixation via session adoption with strict
> mode. Defaults to 0 (disabled).
It was moved to other RFC.
https://wiki.php.net/rfc/session-use-strict-mode
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net