Sec Bug->Doc #64386 [Opn]: No warning on insecure pseudo-random generators
| From: | johannes@php.net | Date: | Fri, 08 Mar 2013 10:50:50 +0000 |
| Subject: | Sec Bug->Doc #64386 [Opn]: No warning on insecure pseudo-random generators | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-9636@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=64386&edit=1
ID: 64386
Updated by: johannes@php.net
Reported by: pawel dot krawczyk at hush dot com
Summary: No warning on insecure pseudo-random generators
Status: Open
-Type: Security
+Type: Documentation Problem
Package: Documentation problem
Operating System: any
PHP Version: Irrelevant
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2013-03-08 10:48:15] pawel dot krawczyk at hush dot com
Description:
------------
---
From manual page: http://www.php.net/function.mt-srand
---
The PHP documentations of pseudorandom related functions is missing warning,
that these functions should not be used for security purposes - generating
session ids, passwords, password resets etc.
The affected functions are mt_rand(), rand(), uniqid(), shuffle(), lcg_value()
Documentation should recommend openssl_random_pseudo_bytes() for these purposes.
Weakness of these functions is pretty well documented here:
http://blog.ptsecurity.com/2012/08/not-so-random-numbers-take-two.html
And there are working exploits:
http://blog.ptsecurity.com/2012/11/workshop-random-numbers-take-two-at.html
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=64386&edit=1