Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:94695 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 68845 invoked from network); 25 Jul 2016 07:09:42 -0000 Received: from unknown (HELO lists.php.net) (127.0.0.1) by localhost with SMTP; 25 Jul 2016 07:09:42 -0000 Authentication-Results: pb1.pair.com header.from=me@daveyshafik.com; sender-id=unknown Authentication-Results: pb1.pair.com smtp.mail=me@daveyshafik.com; spf=permerror; sender-id=unknown Received-SPF: error (pb1.pair.com: domain daveyshafik.com from 209.85.216.171 cause and error) X-PHP-List-Original-Sender: me@daveyshafik.com X-Host-Fingerprint: 209.85.216.171 mail-qt0-f171.google.com Received: from [209.85.216.171] ([209.85.216.171:35544] helo=mail-qt0-f171.google.com) by pb1.pair.com (ecelerity 2.1.1.9-wez r(12769M)) with ESMTP id E5/A0-61920-43BB5975 for ; Mon, 25 Jul 2016 03:09:40 -0400 Received: by mail-qt0-f171.google.com with SMTP id x25so92317573qtx.2 for ; Mon, 25 Jul 2016 00:09:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=daveyshafik-com.20150623.gappssmtp.com; s=20150623; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=+v+NI8odMiaKHPVbzZoh3awFmDISxmRVB0RRH68JLss=; b=gcfheu6DyxxZHNIsArehBprsWfpzWsdU1JTxbKzepEwUxLUlm9a480dAvet66Z80qV MHEVX2T/YtcmSNfiJ5aIHi7ttbDuwmSKSGdkNuLLOqgexh+EuR/BExIWFm4+B/Cu4ubC jtW2GDiVMLsFI6aum4spktIxhJAROA/lZLpNnpGNi6XXsNN6ULBsQ+FCS1m1DA7IOWS6 1WuNe0cO+B+275AcaoWsm926a5HJp3GYEgyaO8wODFBr7mOkvDkcbUwBzNr5fXHbcWsl gXY8atym81XpOlboEMcVti2PHn5JjbkRu38OpEK96GFPcm4t3637xgaLBLjdLt37qCdr YI/A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=+v+NI8odMiaKHPVbzZoh3awFmDISxmRVB0RRH68JLss=; b=We8oO9mNOJsFSFNS6m12ieG8yWSVJJLmgTyhlV/eh+epqvQ5tCUDbRCL9l2NONjz7d +CmEI3lrv6bVzu4ZQsOay7cW0K01RdDFcSAlNhOYsCgj9YCSnvBRPxUW287ox3GClGnv 4D8fuzmnLV1RuS1rNr+BPW6Dpb31T/6s2oDqW/kzhUmNfS+wF3WNtThyJig0Ce+JBKDl 3gipeBrknI0uOAwdOY6aFUo5jfis2n0aTTPizCFeBvcK27KXmVLkysDRSoOl586AX1lL k8LcDuFwA36kF4hsbVZLkYpiJaLouhh1FKH3b5jK5R5YOnO2WWgcnE8ERslIcHVemepf Oc1w== X-Gm-Message-State: AEkoousEj/GauVnfg3JXpWUagu+EaVNWYe0XKMuZYPVGFWVFlfEGkTK5yLoYbC8oSd0S8GJ71wswXn7djktVMlG9 X-Received: by 10.200.45.181 with SMTP id p50mr27382013qta.31.1469430577660; Mon, 25 Jul 2016 00:09:37 -0700 (PDT) MIME-Version: 1.0 Sender: me@daveyshafik.com Received: by 10.237.55.138 with HTTP; Mon, 25 Jul 2016 00:09:37 -0700 (PDT) In-Reply-To: References: Date: Mon, 25 Jul 2016 00:09:37 -0700 X-Google-Sender-Auth: ZkqJKONhVFJELu4SO5S79lBQ9eU Message-ID: To: Yasuo Ohgaki Cc: "internals@lists.php.net" Content-Type: multipart/alternative; boundary=001a113f07309ac14d053870772e Subject: Re: [PHP-DEV] [RFC][VOTE] Session ID without hashing - Reopened From: davey@php.net (Davey Shafik) --001a113f07309ac14d053870772e Content-Type: text/plain; charset=UTF-8 My suggestion: Re-start the vote, three options: Yes, new defaults (BC Break), Yes, old defaults (no BC break), No OR: add a second vote to the page, with: Use new defaults (BC Break), Use Old Defaults (No BC Break) On Sun, Jul 24, 2016 at 6:52 PM, Yasuo Ohgaki wrote: > Hi all, > > I would like to ask the default session ID string preference. > > Details of guessing an active session ID is described in previous mail. > Please refer it for details. > > On Sun, Jul 24, 2016 at 4:57 PM, Yasuo Ohgaki wrote: > > I don't mind pausing vote to have consensus on how many bits for > > session ID string is preferred. > > Current default is 128 bits with 32 chars. (Hex string which has 4 > bits per char) > Pros: Compatible with current default. > Cons: Weaker than proposed default > > Proposed default is 240 bits with 48 chars. (Special form which has 5 > bits per char) > Pros: Stronger than current default. > Cons: Incompatible with current default. > > 128 bits would be strong enough with CSPRNG, while 240 bits would be > preferred as precaution. > Which default would you prefer? > > I would like to restart vote based on the result. > > Thank you! > > -- > Yasuo Ohgaki > yohgaki@ohgaki.net > --001a113f07309ac14d053870772e--