Doc #81384 [Opn->Ver]: Secureness of GMP random functions undocumented

From: Date: Thu, 26 Aug 2021 10:33:54 +0000
Subject: Doc #81384 [Opn->Ver]: Secureness of GMP random functions undocumented
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-19110@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81384&edit=1

 ID:                 81384
 Updated by:         cmb@php.net
 Reported by:        michelbach94 at gmail dot com
 Summary:            Secureness of GMP random functions undocumented
-Status:             Open
+Status:             Verified
 Type:               Documentation Problem
 Package:            GNU MP related
 Operating System:   any
 PHP Version:        8.0.9
 Block user comment: N
 Private report:     N

 New Comment:

gmp_random_bits(), gmp_random() and gmp_random_range() call
mpz_urandomb() and mpz_urandomm(), respectively, internally, and
these names suggest that urandom is used as source of randomness,
but this is not explicitly documented[1], so possibly that "u"
just refers to the uniform distribution.

So, yes, if in doubt don't use these numbers for cryptographic
purposes.

[1] <https://gmplib.org/manual/Integer-Random-Numbers>


Previous Comments:
------------------------------------------------------------------------
[2021-08-26 09:12:50] michelbach94 at gmail dot com

Description:
------------
Usually, the documentation of PHP functions that return randomness says whether the respective
function is cryptographically secure. However, this is not the case with the GMP randomness
functions gmp_random_bits() and gmp_random_range() (nor with the deprecated gmp_random()).

From a Google search, I found that these functions are not cryptographically secure sources of
randomness (https://stackoverflow.com/a/56377850). This should be added to the documentation as
PHP's GMP implementation being able to handle large numbers is very welcoming to the
implementation of cryptographic primitives.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=81384&edit=1


Thread (3 messages)

« previous php.doc.bugs (#19110) next »