Edit report at https://bugs.php.net/bug.php?id=64386&edit=1
ID: 64386
Updated by: cmb@php.net
Reported by: pawel dot krawczyk at hush dot com
Summary: No warning on insecure pseudo-random generators
-Status: Open
+Status: Closed
Type: Documentation Problem
Package: Documentation problem
Operating System: any
PHP Version: Irrelevant
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation better.
Previous Comments:
------------------------------------------------------------------------
[2016-06-14 14:52:24] cmb@php.net
Automatic comment from SVN on behalf of cmb
Revision: http://svn.php.net/viewvc/?view=revision&revision=339348
Log: Fix #64386: No warning on insecure pseudo-random generators
------------------------------------------------------------------------
[2013-03-08 10:48:15] pawel dot krawczyk at hush dot com
Description:
------------
---
From manual page: http://www.php.net/function.mt-srand
---
The PHP documentations of pseudorandom related functions is missing warning,
that these functions should not be used for security purposes - generating
session ids, passwords, password resets etc.
The affected functions are mt_rand(), rand(), uniqid(), shuffle(), lcg_value()
Documentation should recommend openssl_random_pseudo_bytes() for these purposes.
Weakness of these functions is pretty well documented here:
http://blog.ptsecurity.com/2012/08/not-so-random-numbers-take-two.html
And there are working exploits:
http://blog.ptsecurity.com/2012/11/workshop-random-numbers-take-two-at.html
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=64386&edit=1