On Fri, Apr 17, 2020 at 07:59:01PM -0500, Derek Martin wrote:
This is utterly pointless. This may come off as harsh but please understand that's not intended. I just want to be completely clear hee so there is no misunderstanding or equivocation.

I would also note that the current message id generation algorithm is deterministic. It's easy to understand how it generates, and to know the exact limitations where it might fail. Swapping out those bits of uniqueness with a random() call takes away the determinism.

The tiny (in my opinion too) information leaks, are not worth that trade-off.

--
Kevin J. McCarthy
GPG Fingerprint: 8975 A9B3 3AA3 7910 385C  5308 ADEF 7684 8031 6BDA

Attachment: signature.asc
Description: PGP signature

Reply via email to