Doc #54299 [Opn->Csd]: Error in a comment about salt generation (crypto)
| From: | aharvey@php.net | Date: | Fri, 18 Mar 2011 04:09:34 +0000 |
| Subject: | Doc #54299 [Opn->Csd]: Error in a comment about salt generation (crypto) | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-6102@lists.php.net to get a copy of this message | ||
Edit report at http://bugs.php.net/bug.php?id=54299&edit=1
ID: 54299
Updated by: aharvey@php.net
Reported by: krewecherl at gmail dot com
Summary: Error in a comment about salt generation (crypto)
-Status: Open
+Status: Closed
Type: Documentation Problem
Package: Documentation problem
PHP Version: Irrelevant
-Assigned To:
+Assigned To: aharvey
Block user comment: N
Private report: N
New Comment:
Note updated; it'll take a little while to propagate out to the
mirrors.
Thanks!
Previous Comments:
------------------------------------------------------------------------
[2011-03-18 04:56:16] krewecherl at gmail dot com
Description:
------------
The comment by "thegreatall at gmail dot com" on the manual page for
mt_rand() describes a method for quickly generating a pseudo-random salt
for password hashes. One of the constants given in the example is
incorrect and can lead a smaller range from which the random numbers
will be selected.
The line -
base_convert(mt_rand(0x1679616, 0x39AA3FF, 10, 36);
- should be changed to either -
base_convert(mt_rand(1679616, 0x39AA3FF, 10, 36);
- or, if we want to keep the hex format, to -
base_convert(mt_rand(0x19A100, 0x39AA3FF, 10, 36);
Rationale: the number 0x19A100 (= 1679616 in decimal) will be
represented as 10000 in base-36, which is the intended value, whereas
the given number 0x1679616 will be represented as e13iu in base-36.
Comment ID: 102318
Link: http://php.net/manual/en/function.mt-rand.php#102318
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/bug.php?id=54299&edit=1