Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:73324 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 71350 invoked from network); 20 Mar 2014 08:31:19 -0000 Received: from unknown (HELO lists.php.net) (127.0.0.1) by localhost with SMTP; 20 Mar 2014 08:31:19 -0000 Authentication-Results: pb1.pair.com smtp.mail=yohgaki@gmail.com; spf=pass; sender-id=pass Authentication-Results: pb1.pair.com header.from=yohgaki@gmail.com; sender-id=pass Received-SPF: pass (pb1.pair.com: domain gmail.com designates 209.85.217.181 as permitted sender) X-PHP-List-Original-Sender: yohgaki@gmail.com X-Host-Fingerprint: 209.85.217.181 mail-lb0-f181.google.com Received: from [209.85.217.181] ([209.85.217.181:42732] helo=mail-lb0-f181.google.com) by pb1.pair.com (ecelerity 2.1.1.9-wez r(12769M)) with ESMTP id 86/36-33112-757AA235 for ; Thu, 20 Mar 2014 03:31:19 -0500 Received: by mail-lb0-f181.google.com with SMTP id c11so337853lbj.26 for ; Thu, 20 Mar 2014 01:31:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc:content-type; bh=YHRwKYK/1CYaY7sibmgN4bEUri1tde2Ee/MWFz8k7w0=; b=0ELMN+1ISBHd7YYQdMRjgtyqQbUlXg48bjyeAPki36BHtd4T2CUcISDm0wSEqKG0ZJ ZDBgeqh0FjLW3zbXe6g5jb5PrONvZNel7nBP1KKz1y3ejet+S3H5h0Q7V7/g4EvF/ETC QSNikUJzA4+ldSmAmGyTNtLGMtl71C2Qs32fud98oXi/0IO/ps2U0tLEbsBN7TQGTbni J1vQ7PiNjiTZJ4VH+OEiBma9YQSlR8/L9eYWqCPo3t+L05Xlpf2mYT+AOIMj7V+Dk+R/ 5X0Mu9soN4onxNTrXeWVUrgA7kyLYhM2kEe0T0+UyNdMpkj1OfS1L9FCORtnxXX3HXtF ESBg== X-Received: by 10.152.87.71 with SMTP id v7mr29497244laz.10.1395304276533; Thu, 20 Mar 2014 01:31:16 -0700 (PDT) MIME-Version: 1.0 Sender: yohgaki@gmail.com Received: by 10.112.205.73 with HTTP; Thu, 20 Mar 2014 01:30:36 -0700 (PDT) In-Reply-To: <20140320082346.GA61204@mail> References: <20140319080229.GA83863@mail> <20140319111131.GB83863@mail> <20140320082346.GA61204@mail> Date: Thu, 20 Mar 2014 17:30:36 +0900 X-Google-Sender-Auth: k-4nbFDMM3JIYnx913Mg317iyOA Message-ID: To: Mateusz Kocielski Cc: "internals@lists.php.net" Content-Type: multipart/alternative; boundary=001a11c355b2c1a76404f5059722 Subject: Re: [PHP-DEV] [RFC] [Discussion] Secure session_regenerate_id() From: yohgaki@ohgaki.net (Yasuo Ohgaki) --001a11c355b2c1a76404f5059722 Content-Type: text/plain; charset=UTF-8 Hi Mateusz, On Thu, Mar 20, 2014 at 5:23 PM, Mateusz Kocielski wrote: > > > I agree. But we've got more factors here, it's not a simple tool for > > > detection > > > of crimes. If we let "old session" live for x secs, what will happen to > > > changes done to the old session? How do you want to resolve that? We > should > > > find a balance between complexity and security. > > > > > > > > Currently we have poor mitigation. My proposal provides better > mitigation. > > I still don't see how you want to handle inconsistency between sessions. It > seems that your RFC silently ignores that issue. I'm not sure which inconsistency. Could you specify/describe it? Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net --001a11c355b2c1a76404f5059722--