Doc #62966 [Ana->Csd]: Random numbers prediction

From: Date: Sun, 26 Oct 2014 15:57:32 +0000
Subject: Doc #62966 [Ana->Csd]: Random numbers prediction
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-11586@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62966&edit=1 ID: 62966 Updated by: salathe@php.net Reported by: ymaryshev at ptsecurity dot ru Summary: Random numbers prediction -Status: Analyzed +Status: Closed Type: Documentation Problem Package: *General Issues Operating System: All PHP Version: Irrelevant -Assigned To: +Assigned To: salathe Block user comment: N Private report: N New Comment: Fixed in r328689 by aharvey (2012-12-06). Previous Comments: ------------------------------------------------------------------------ [2012-11-28 15:31:12] pajoye@php.net Doc needs to be updated to add the security concerns about the rand and mt_rand set of functions. ------------------------------------------------------------------------ [2012-11-28 13:44:37] ymaryshev at ptsecurity dot ru Fixed issue summary ------------------------------------------------------------------------ [2012-09-20 10:45:53] ymaryshev at ptsecurity dot ru By stronger seeding we mean: 1. Use external sources of entropy as in case of PHPSESSID in newer PHP versions (php_win32_get_random_bytes, urandom, etc). In other words we suggest applying “session.entropy_file/entropy_length” to the seed generating functions, namely lcg_seed() and GENERATE_SEED() 2. Do not use the output of the LCG for generating seed of (mt_)rand (in the GENERATE_SEED macro) ------------------------------------------------------------------------ [2012-09-19 14:21:30] tony2001@php.net How do you propose to fix it in PHP? "Stronger seeding" sounds a bit too general to me. ------------------------------------------------------------------------ [2012-09-06 10:00:48] ymaryshev at ptsecurity dot ru We certainly do not object to it, but we still think that fixing this problem would be a more appropriate solution just for the sake of web apps which do not track recent changes in PHP documentation. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=62966 -- Edit this bug report at https://bugs.php.net/bug.php?id=62966&edit=1

« previous php.doc.bugs (#11586) next »