Re: [bagder/curl] eefeb7: curl_sasl: Extended native DIGEST-MD5 cnonce to be...
Date: Mon, 2 Jun 2014 12:10:27 +0200 (CEST)
On Mon, 2 Jun 2014, Daniel Stenberg wrote:
> If we really want to add more "randomness", wouldn't it be better to call
> Curl_rand() two more times instead? It is getting "real" random data from
> the underlying TLS/crypto library and that is bound to be safer than adding
> the current time.
I suggest this simple patch - see attachment.
It also has the added benefit that once I (finally) add my code that "fakes"
Curl_rand() for debug builds we won't have to have any DEBUGBUILD conditionals
in that code path - having the time/date involved would make that harder.
-- / daniel.haxx.se
- TEXT/x-diff attachment: 0001-sasl-use-Curl_rand-for-random-data.patch