Re: [RFC][VOTE] Improve hash_hkdf() parameter
| From: | Yasuo Ohgaki | Date: | Thu, 13 Apr 2017 08:38:21 +0000 |
| Subject: | Re: [RFC][VOTE] Improve hash_hkdf() parameter | ||
| References: | 1 2 3 4 5 6 7 8 | Groups: | php.doc php.internals |
| Request: | Send a blank email to internals+get-98782@lists.php.net to get a copy of this message | ||
Hi Peiter,
On Thu, Apr 13, 2017 at 5:11 PM, Pieter Hordijk <info@pieterhordijk.com>
wrote:
> To be honest I am afraid of ending up with something like the current state
> of the session docs. Which are imo way too broad / opinionated, non
> English,
> contains utterly confusing examples and / or flat out wrong and broken
> examples.
> Above already resulted in a stream of docs bugs regarding session pages
> and a lot of confused readers.
>
You may consider my opinion as my personal opinion. I don't know of other
than
me who had that opinion then.
After our session discussion, it seems OWASP adopted most of discussed
elements in their doc ;)
https://www.owasp.org/index.php/Session_Management_Cheat_Sheet
Regards,
P.S. My opinion is based on RFC 5869. In addition, it's totally nonsense to
me to have completely different signature for hash_hkdf().
See the difference hash_hmac() and hash_pbkdf2(). hash_pbkdf2() is older
KDF function. I should have mention in the RFC :(
--
Yasuo Ohgaki
yohgaki@ohgaki.net