However even the documentation for this module admits the reasonable possibility of producing a duplicate ID. I haven't studied the module, but an encoding scheme is by its very definition, decodable. Thus the ID produced by this system may well be susceptible to brute force attacks.
I, for one, would be much happier to see a non decodable result, using say an MD5 hash.
jdtoronto | [reply] |