Bug #70150 [Opn->Dup]: $iv = mcrypt_create_iv( $rem, MCRYPT_DEV_URANDOM ); times out

From: Date: Sat, 15 Aug 2015 15:46:20 +0000
Subject: Bug #70150 [Opn->Dup]: $iv = mcrypt_create_iv( $rem, MCRYPT_DEV_URANDOM ); times out
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-195235@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70150&edit=1

 ID:                 70150
 Updated by:         ab@php.net
 Reported by:        gessel at blackrosetech dot com
 Summary:              $iv = mcrypt_create_iv( $rem, MCRYPT_DEV_URANDOM
                     ); times out
-Status:             Open
+Status:             Duplicate
 Type:               Bug
 Package:            mcrypt related
 Operating System:   FreeBSD 10.1-RELEASE #0 r285883
 PHP Version:        5.5.27
 Block user comment: N
 Private report:     N

 New Comment:

@gessel, please check the latest 5.6 or 7 branch/snapshot (no release yet). This is likely a
duplicate of bug #69833.

Thanks.


Previous Comments:
------------------------------------------------------------------------
[2015-07-27 17:03:45] cmb@php.net

MCRYPT_DEV_URANDOM|MCRYPT_RAND has the same behavior as
MCRYPT_RAND, i.e. the else clause[1] will be processed. I have
deleted Cory's note.

[1] <https://github.com/php/php-src/blob/php-5.6.11/ext/mcrypt/mcrypt.c#L1426-L1469>

------------------------------------------------------------------------
[2015-07-27 07:24:50] gessel at blackrosetech dot com

Description:
------------
---
From manual page: http://www.php.net/function.mcrypt-create-iv
---

MediaWiki's MWCryptRand.php calls  
 $iv = mcrypt_create_iv( $rem, MCRYPT_DEV_URANDOM );
This times out on FreeBSD without returning a value (even with max_execution_time set to 3000).  

modifying the call to 
  $iv = mcrypt_create_iv( $rem, MCRYPT_DEV_URANDOM|MCRYPT_RAND );
returns as expected, however, the MW dev is concerned that MCRYPT_RAND is not cryptographically
secure, and that CC's note at https://secure.php.net/manual/en/function.mcrypt-create-iv.php#117047
is incorrect and that this piped construction will return "3" (rather than 0,1,2 or as
Cory states, first attempt 1 and if that isn't available, try 2) and with "3" will
always initialize with the crytographically insecure MCRYPT_RAND.

Test script:
---------------
$iv = mcrypt_create_iv( $rem, MCRYPT_DEV_URANDOM );



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=70150&edit=1


Thread (3 messages)

« previous php.bugs (#195235) next »