Req #67795 [Opn->Sus]: PHP lacks a modern RNG

From: Date: Wed, 08 Apr 2020 09:11:41 +0000
Subject: Req #67795 [Opn->Sus]: PHP lacks a modern RNG
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-226474@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67795&edit=1 ID: 67795 Updated by: cmb@php.net Reported by: ryacko at gmail dot com Summary: PHP lacks a modern RNG -Status: Open +Status: Suspended Type: Feature/Change Request Package: Math related PHP Version: Irrelevant Block user comment: N Private report: N New Comment: This feature request obviously requires discussion regarding the details. However, this bug tracker is not suitable for these kind of discussion, so please bring this request up on the internals mailing list[1]. For the time being, I'm suspending this ticket. Previous Comments: ------------------------------------------------------------------------ [2014-08-14 05:23:40] levim@php.net Oops, I somehow responded on the wrong tab. My apologies! ------------------------------------------------------------------------ [2014-08-14 05:23:01] levim@php.net Ironically, this was fixed long ago but the bug has reoccurred now that we are using Google. ------------------------------------------------------------------------ [2014-08-06 10:03:06] ryacko at gmail dot com https://www.cisuc.uc.pt/publication/show/2676 Forgot to mention Tyche. ------------------------------------------------------------------------ [2014-08-06 09:47:55] ryacko at gmail dot com Modern RNG are very fast and have better distribution. The Mersenne twister has weak seeds, as well as a small seed state. Several good pseudo random number generators include: - http://www.iro.umontreal.ca/~panneton/WELLRNG.html (superior equidistribution) - ChaCha4 (on some chips it has less than a cycle per byte) - 128-bit AES counter (on chips with AES instruction, it could very well reach 3 gigabytes per second) - http://www.math.sci.hiroshima-u.ac.jp/~%20m-mat/MT/SFMT/index.html Mersenne Twister SIMD, 4 times faster I suggest ChaCha4 or 128-bit AES counter since with either of those one could include stream position in the function. I suggest the following functions: b_srand( string $seed [, $get_additional_entropy] ) it automatically seeds using an md5 hash of the time. Also includes an option to get additional entropy in the same fashion that session.entropy_length gets entropy. b_rand( int $min , int $max, [, int $stream_position] ) An obvious use would be a procedurally generated browser game. ------------------------------------------------------------------------ [2014-08-06 08:06:30] ryacko at gmail dot com Description: ------------ Modern RNG are very fast and have better distribution. The Mersenne twister has weak seeds, as well as a small seed state. Several good pseudo random number generators include: - http://www.iro.umontreal.ca/~panneton/WELLRNG.html (superior equidistribution) - ChaCha4 (on some chips it has less than a cycle per byte) - 128-bit AES counter (on chips with AES instruction, it could very well reach 3 gigabytes per second) - http://www.math.sci.hiroshima-u.ac.jp/~%20m-mat/MT/SFMT/index.html Mersenne Twister SIMD, 4 times faster I suggest ChaCha4 or 128-bit AES counter since with either of those one could include stream position in the function. I suggest the following functions: b_srand( [, $get_additional_entropy] ) it automatically seeds using an md5 hash of the time. Also includes an option to get additional entropy in the same fashion that session.entropy_length gets entropy. b_rand( int $min , int $max, [, int $stream_position] ) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67795&edit=1

« previous php.bugs (#226474) next »