cURL / Mailing Lists / curl-library / Single Mail


Re: [bagder/curl] eefeb7: curl_sasl: Extended native DIGEST-MD5 cnonce to be...

From: Daniel Stenberg <>
Date: Mon, 2 Jun 2014 12:10:27 +0200 (CEST)

On Mon, 2 Jun 2014, Daniel Stenberg wrote:

> If we really want to add more "randomness", wouldn't it be better to call
> Curl_rand() two more times instead? It is getting "real" random data from
> the underlying TLS/crypto library and that is bound to be safer than adding
> the current time.

I suggest this simple patch - see attachment.

It also has the added benefit that once I (finally) add my code that "fakes"
Curl_rand() for debug builds we won't have to have any DEBUGBUILD conditionals
in that code path - having the time/date involved would make that harder.


List admin:

Received on 2014-06-02