Re: More secure defaults for openssl_public_encrypt() & openssl_private_decrypt()

From: Date: Mon, 12 Dec 2016 15:34:07 +0000
Subject: Re: More secure defaults for openssl_public_encrypt() & openssl_private_decrypt()
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-97370@lists.php.net to get a copy of this message
On Mon, Dec 12, 2016 at 10:26 AM, Sammy Kaye Powers <me@sammyk.me> wrote: > Hey internals! > > As pointed out in Paragon's excellent blog post, > openssl_public_encrypt() & openssl_private_decrypt() defaults to the > insecure OPENSSL_PKCS1_PADDING constant. > > > https://paragonie.com/blog/2016/12/everything-you-know-about-public-key-encryption-in-php-is-wrong#php-openssl-rsa-bad-default > > What are your thoughts about deprecating OPENSSL_PKCS1_PADDING and > using OPENSSL_PKCS1_OAEP_PADDING as the new default? > > Thanks, > Sammy Kaye Powers > sammyk.me > > -- > PHP Internals - PHP Runtime Development Mailing List > To unsubscribe, visit: http://www.php.net/unsub.php > There was a little bit of discussion here previously. http://externals.io/thread/442#email-12842 Scott Arciszewski Chief Development Officer Paragon Initiative Enterprises <https://paragonie.com>

« previous php.internals (#97370) next »