Req #72833 [Opn->Sus]: Use RDRND operand instead of Mersenne Twister

From: Date: Sun, 14 Aug 2016 16:11:50 +0000
Subject: Req #72833 [Opn->Sus]: Use RDRND operand instead of Mersenne Twister
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203279@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72833&edit=1 ID: 72833 Updated by: requinix@php.net Reported by: benjamin dot balet at gmail dot com Summary: Use RDRND operand instead of Mersenne Twister -Status: Open +Status: Suspended Type: Feature/Change Request Package: *Math Functions PHP Version: Irrelevant Block user comment: N Private report: N New Comment: This is definitely the kind of thing that needs to be talked about on the internals list instead of here. http://php.net/mailing-lists.php Throwing out a few comments: - rand and mt_rand are soft-deprecated in favor of random_int/bytes anyways (PHP 7+); those defer the random generation to the OS (which is how it should be) - There are concerns about RdRand being potentially backdoor-able - Linux's urandom may factor in RdRand already, so using that is at least as good as using RdRand alone - Windows has a crypto API; haven't seen anything to indicate whether or how Windows uses RdRand Previous Comments: ------------------------------------------------------------------------ [2016-08-14 15:41:46] benjamin dot balet at gmail dot com Description: ------------ There are many non-cryptographic applications using the rand function of PHP and I was wondering if it is worth the effort to implement a call to the hardware function RDRND if it is supported by the platform. Benefits of using RDRND: * It is seeded with a true random number generator. * Better source of random numbers than Mersenne Twister algorithm. Concerns of using RDRND: * This operand is available on recent Intel CPUs (Ivy Bridge) and only in the coming Zen AMD Architecture. * A bit slower than Mersenne Twister (if we omit the time it takes to seed the algo from the benchmark). Benefits of current PHP implementation: * The code is faster than RDRND if we don't count the generation of the seed number. Concerns of current PHP implementation: * A hard-coded limit of a 32 bits integer causes the need of two calls and a shift of the result so as to create a 64 bits number. * If the generator is not seeded, the PHP makes a syscall in order to get the PID of PHP, whereas RDRND is seeded. * Maybe considered as obsolete (see #67795). The implementation (ext/standard/mt_rand.c) would look like #ifdef __RDRND__ #include <immintrin.h> // No need to call GENERATE_SEED() # ifdef ZEND_ENABLE_ZVAL_LONG64 // Call to _rdrand64_step(uint64_t*); # else // Call to _rdrand32_step(uint32_t*); # endif #else //current PHP implementation #endif ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72833&edit=1

« previous php.bugs (#203279) next »