Sec Bug->Doc #64386 [Opn]: No warning on insecure pseudo-random generators

From: Date: Fri, 08 Mar 2013 10:50:50 +0000
Subject: Sec Bug->Doc #64386 [Opn]: No warning on insecure pseudo-random generators
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-9636@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64386&edit=1 ID: 64386 Updated by: johannes@php.net Reported by: pawel dot krawczyk at hush dot com Summary: No warning on insecure pseudo-random generators Status: Open -Type: Security +Type: Documentation Problem Package: Documentation problem Operating System: any PHP Version: Irrelevant Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2013-03-08 10:48:15] pawel dot krawczyk at hush dot com Description: ------------ --- From manual page: http://www.php.net/function.mt-srand --- The PHP documentations of pseudorandom related functions is missing warning, that these functions should not be used for security purposes - generating session ids, passwords, password resets etc. The affected functions are mt_rand(), rand(), uniqid(), shuffle(), lcg_value() Documentation should recommend openssl_random_pseudo_bytes() for these purposes. Weakness of these functions is pretty well documented here: http://blog.ptsecurity.com/2012/08/not-so-random-numbers-take-two.html And there are working exploits: http://blog.ptsecurity.com/2012/11/workshop-random-numbers-take-two-at.html ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=64386&edit=1

« previous php.doc.bugs (#9636) next »