Bug #67795 [NEW]: PHP lacks a modern RNG
| From: | ryacko at gmail dot com | Date: | Wed, 06 Aug 2014 08:06:31 +0000 |
| Subject: | Bug #67795 [NEW]: PHP lacks a modern RNG | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-186996@lists.php.net to get a copy of this message | ||
From: ryacko at gmail dot com
Operating system:
PHP version: Irrelevant
Package: Math related
Bug Type: Bug
Bug description:PHP lacks a modern RNG
Description:
------------
Modern RNG are very fast and have better distribution. The Mersenne
twister has weak seeds, as well as a small seed state.
Several good pseudo random number generators include:
- http://www.iro.umontreal.ca/~panneton/WELLRNG.html
(superior
equidistribution)
- ChaCha4 (on some chips it has less than a cycle per byte)
- 128-bit AES counter (on chips with AES instruction, it could very well
reach 3 gigabytes per second)
- http://www.math.sci.hiroshima-u.ac.jp/~%20m-mat/MT/SFMT/index.html
Mersenne Twister SIMD, 4 times faster
I suggest ChaCha4 or 128-bit AES counter since with either of those one
could include stream position in the function.
I suggest the following functions:
b_srand( [, $get_additional_entropy] ) it automatically seeds using an
md5 hash of the time. Also includes an option to get additional entropy
in the same fashion that session.entropy_length gets entropy.
b_rand( int $min , int $max, [, int $stream_position] )
--
Edit bug report at https://bugs.php.net/bug.php?id=67795&edit=1
--