rfc:precise_session_management

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
rfc:precise_session_management [2016/03/09 11:30] – Fix wrong function mentioned. yohgakirfc:precise_session_management [2017/09/22 13:28] (current) – external edit 127.0.0.1
Line 5: Line 5:
   * Date Updated: 2016-01-29   * Date Updated: 2016-01-29
   * Author: Yasuo Ohgaki <yohgaki@php.net>   * Author: Yasuo Ohgaki <yohgaki@php.net>
-  * Status: Under Discussion+  * Status: Declined 
   * First Published at: http://wiki.php.net/rfc/session_regenerate_id   * First Published at: http://wiki.php.net/rfc/session_regenerate_id
   * Renamed: https://wiki.php.net/rfc/precise_session_management   * Renamed: https://wiki.php.net/rfc/precise_session_management
Line 266: Line 266:
 https://www.owasp.org/index.php/Mobile_Top_10_2014-M9#Lack_of_Adequate_Timeout_Protection https://www.owasp.org/index.php/Mobile_Top_10_2014-M9#Lack_of_Adequate_Timeout_Protection
  
-=== Why this is secure than now ===+=== Why this is more secure than now ===
  
 Currently, users must call session_regenerate_id(FALSE) to have relatively stable session. Therefore, old session data is valid as long as it is accessed even if it should be discarded as invalid session. Attackers can take advantage of this behavior to keep stolen session forever, disabling GC by periodic access to stolen session. Currently, users must call session_regenerate_id(FALSE) to have relatively stable session. Therefore, old session data is valid as long as it is accessed even if it should be discarded as invalid session. Attackers can take advantage of this behavior to keep stolen session forever, disabling GC by periodic access to stolen session.
Line 427: Line 427:
 Vote starts 2016-03-09-09:00(UTC) and ends 2016-03-23-09:00(UTC) Vote starts 2016-03-09-09:00(UTC) and ends 2016-03-23-09:00(UTC)
  
-<doodle title="Precise Session Data Management" auth="yohgaki" voteType="single" closed="false">+<doodle title="Precise Session Data Management" auth="yohgaki" voteType="single" closed="true">
    * Yes    * Yes
    * No    * No
rfc/precise_session_management.1457523047.txt.gz · Last modified: 2017/09/22 13:28 (external edit)