Doc #64386 [Opn->Csd]: No warning on insecure pseudo-random generators

From: Date: Tue, 14 Jun 2016 14:52:51 +0000
Subject: Doc #64386 [Opn->Csd]: No warning on insecure pseudo-random generators
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-13514@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64386&edit=1

 ID:                 64386
 Updated by:         cmb@php.net
 Reported by:        pawel dot krawczyk at hush dot com
 Summary:            No warning on insecure pseudo-random generators
-Status:             Open
+Status:             Closed
 Type:               Documentation Problem
 Package:            Documentation problem
 Operating System:   any
 PHP Version:        Irrelevant
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.

Thank you for the report, and for helping us make our documentation better.


Previous Comments:
------------------------------------------------------------------------
[2016-06-14 14:52:24] cmb@php.net

Automatic comment from SVN on behalf of cmb
Revision: http://svn.php.net/viewvc/?view=revision&revision=339348
Log: Fix #64386: No warning on insecure pseudo-random generators

------------------------------------------------------------------------
[2013-03-08 10:48:15] pawel dot krawczyk at hush dot com

Description:
------------
---
From manual page: http://www.php.net/function.mt-srand
---
The PHP documentations of pseudorandom related functions is missing warning, 
that these functions should not be used for security purposes - generating 
session ids, passwords, password resets etc.

The affected functions are mt_rand(), rand(), uniqid(), shuffle(), lcg_value()

Documentation should recommend openssl_random_pseudo_bytes() for these purposes.

Weakness of these functions is pretty well documented here:

http://blog.ptsecurity.com/2012/08/not-so-random-numbers-take-two.html

And there are working exploits:

http://blog.ptsecurity.com/2012/11/workshop-random-numbers-take-two-at.html



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=64386&edit=1


Thread (1 message)

  • cmb@php.net
  • Unknown Message
    • cmb@php.net
« previous php.doc.bugs (#13514) next »