Re: Re: [RFC][DISCUSSION] Improve uniqid() uniqueness
| From: | Yasuo Ohgaki | Date: | Tue, 18 Oct 2016 11:37:59 +0000 |
| Subject: | Re: Re: [RFC][DISCUSSION] Improve uniqid() uniqueness | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-96426@lists.php.net to get a copy of this message | ||
On Tue, Oct 18, 2016 at 8:00 PM, Lester Caine <lester@lsces.co.uk> wrote:
> On 18/10/16 11:02, Niklas Keller wrote:
>>> 'Suppliers' should perhaps be helped to configure their systems so the
>>> > users can use things, but things like /dev/urandom may need some
>>> > additional notes to help identify problems when frameworks like owncloud
>>> > start throwing errors. As Niklas says it's shared environments where
>>> > this one may bite.
>>> >
>> Just to be clear: I don't argue that those systems are broken, I just say
>> that there is a BC break for those systems and that this has to be
>> documented.
>
> Yes ... and the RFC process is at least part of the documentation.
The patch committed is pure bug fix.
uniqid() is simply _broken_ because it does not provide expected uniqueness due
to timestamp based php_combined_lcg(). (I added large warning to the manual
recently, though)
unique id (time stamp) + entropy (timestamp based entropy)
Who argue result is reasonably unique?
Who don't use NTP to adjust system time?
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net