3 ms·
> If your database's primary key is 32 bits (SERIAL in PostgreSQL, INT(11) in MySQL, etc.), you want at least 8 bytes for the selector. 32 bits = 4 bytes. How
by foo101 10y ago
> If your database's primary key is 32 bits (SERIAL in PostgreSQL, INT(11) in MySQL, etc.), you want at least 8 bytes for the selector.
32 bits = 4 bytes. How can we store a 8 byte selector in a 32 bit integer then?
- CiPHPerCoder 10y agoYou're using a separate column (which is a CHAR, VARCHAR, or TEXT field) to store the selector INSTEAD of the database primary key. From the example query: SELECT tokenid, validator, userid FROM password_reset_tokens WHERE selector = :selector AND NOW() < expire_time The columns in this query: - tokenid -- the primary key - selector -- some text data, used in WHERE clause - validator -- some text data, not used in WHERE clause - expire_time -- timestamp You have a 50% chance of a collision in a 64-bit space after 2^32 values. That means you have a 50% chance of it happening once after you exhaust your 32-bit primary key space. https://en.wikipedia.org/wiki/Birthday_attack https://en.wikipedia.org/wiki/Birthday_attack