Page 2 of 2

Re: PHP 7.2 Support?

Posted: Mon May 06, 2019 3:44 am
by ADD Creative
The pull request on GitHub will work and remove the PHP Warning about the Initialization Vector. However, it should be noted that in does not have any message authentication. So would more be susceptible to some types attacks.

Also the Initialization Vector could be used more than once.

Re: PHP 7.2 Support?

Posted: Mon May 06, 2019 3:54 am
by straightlight
"It is obvious that this contest cannot be decided by our knowledge of the Forceā€¦ but by our skills with a ... light-sodium!"

https://github.com/opencart/opencart/pu ... -489457948

Post addressed due to authentication method missing to return an event message.

Re: PHP 7.2 Support?

Posted: Mon May 06, 2019 6:50 am
by ADD Creative
I've also noticed the pull request on GitHub could use the IV multiple times. An IV should only be used once.

Re: PHP 7.2 Support?

Posted: Mon May 06, 2019 9:04 am
by straightlight
Correct, I've noticed it as well. With the sodium solution, let's see if that reduces the indicent requests.