Re: [PHP-DEV] More secure defaults for openssl_public_encrypt() & openssl_private_decrypt()

2016-12-12 Thread Andreas Heigl
Am 12.12.16 um 16:26 schrieb Sammy Kaye Powers: > Hey internals! > > As pointed out in Paragon's excellent blog post, > openssl_public_encrypt() & openssl_private_decrypt() defaults to the > insecure OPENSSL_PKCS1_PADDING constant. > >

Re: [PHP-DEV] More secure defaults for openssl_public_encrypt() & openssl_private_decrypt()

2016-12-12 Thread Scott Arciszewski
On Mon, Dec 12, 2016 at 10:26 AM, Sammy Kaye Powers wrote: > Hey internals! > > As pointed out in Paragon's excellent blog post, > openssl_public_encrypt() & openssl_private_decrypt() defaults to the > insecure OPENSSL_PKCS1_PADDING constant. > >

[PHP-DEV] More secure defaults for openssl_public_encrypt() & openssl_private_decrypt()

2016-12-12 Thread Sammy Kaye Powers
Hey internals! As pointed out in Paragon's excellent blog post, openssl_public_encrypt() & openssl_private_decrypt() defaults to the insecure OPENSSL_PKCS1_PADDING constant.