Bug #70744 [Opn]: random_bytes() should not use linc arc4random

From: Date: Tue, 20 Oct 2015 16:48:55 +0000
Subject: Bug #70744 [Opn]: random_bytes() should not use linc arc4random
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196710@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70744&edit=1 ID: 70744 User updated by: fsb at thefsb dot org Reported by: fsb at thefsb dot org Summary: random_bytes() should not use linc arc4random Status: Open Type: Bug Package: *Encryption and hash functions Operating System: All except Windows PHP Version: 7.0.0RC5 Block user comment: N Private report: N New Comment: Fwiw, asking in Freenode #openbsd this morning: 11:43 tom[] is there a reliable way for a program to determine if the linked libc arc4random (assuming there is one) is ChaCha20 or heirloom 96 ARC4? 11:47 Straylight tom[]: if the OS version is >= 5.5 (uname(3) should tell you that?), then it's chaha 11:48 tom[] Straylight: yes, but then this eventually has to evolve into a small database for all the BSDs 11:49 Straylight tom[]: If you're asking for a mechanism that works across any possible BSD derivative, then it doesn't exist In which I am tom[] and time is UTC-04:00. I don't know who is Straylight. [Sorry again for suggesting in OP that NetBSD introduced ChaCha20. It was OpenBSD in 2013.] Previous Comments: ------------------------------------------------------------------------ [2015-10-20 14:57:28] fsb at thefsb dot org CORRECTION: OpenBSD since 5.5 uses ChaCha20. But random_bytes() use of arc4random_buf() remains unsafe. ------------------------------------------------------------------------ [2015-10-19 22:04:57] fsb at thefsb dot org Description: ------------ ARC4 is known to be unsafe for use either as a stream cipher or a CSPRNG. You can read about it on Wikipedia and elsewhere. As far as I can tell, until recently, all implementations of the libc arc4random functions are based on David Mazieres 1996 implementation of ARC4. In November 2014, NetBSD replaced the cipher underneath libc's arc4random API with ChaCha20, a modern stream cipher currently considered safe. But this change hasn't made it into a NetBSD release yet. OS X, FreeBSD and OpenBSD have not yet incorporated NetBSD's source code change and I don't know if they will. So for the time being we have to assume that libc arc4random is ARC4 cipher and therefore unsafe. This code branch should be removed. https://github.com/php/php-src/blob/php-7.0.0RC5/ext/standard/random.c#L91 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70744&edit=1

« previous php.bugs (#196710) next »