Bug #67795 [NEW]: PHP lacks a modern RNG

From: Date: Wed, 06 Aug 2014 08:06:31 +0000
Subject: Bug #67795 [NEW]: PHP lacks a modern RNG
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-186996@lists.php.net to get a copy of this message
From: ryacko at gmail dot com Operating system: PHP version: Irrelevant Package: Math related Bug Type: Bug Bug description:PHP lacks a modern RNG Description: ------------ Modern RNG are very fast and have better distribution. The Mersenne twister has weak seeds, as well as a small seed state. Several good pseudo random number generators include: - http://www.iro.umontreal.ca/~panneton/WELLRNG.html (superior equidistribution) - ChaCha4 (on some chips it has less than a cycle per byte) - 128-bit AES counter (on chips with AES instruction, it could very well reach 3 gigabytes per second) - http://www.math.sci.hiroshima-u.ac.jp/~%20m-mat/MT/SFMT/index.html Mersenne Twister SIMD, 4 times faster I suggest ChaCha4 or 128-bit AES counter since with either of those one could include stream position in the function. I suggest the following functions: b_srand( [, $get_additional_entropy] ) it automatically seeds using an md5 hash of the time. Also includes an option to get additional entropy in the same fashion that session.entropy_length gets entropy. b_rand( int $min , int $max, [, int $stream_position] ) -- Edit bug report at https://bugs.php.net/bug.php?id=67795&edit=1 --

« previous php.bugs (#186996) next »