[RFC] Improve openssl_random_pseudo_bytes()
| From: | Sammy Kaye Powers | Date: | Fri, 19 Oct 2018 20:46:52 +0000 |
| Subject: | [RFC] Improve openssl_random_pseudo_bytes() | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-103345@lists.php.net to get a copy of this message | ||
Hi internals friends!
I'd like to start a discussion on the "Improve
openssl_random_pseudo_bytes()" RFC:
https://wiki.php.net/rfc/improve-openssl-random-pseudo-bytes
TL;DR:
CSPRNG implementations should always fail closed so this change would
make
openssl_random_pseudo_bytes() fail closed.
The second $crypto_strong parameter doesn't do anything despite the
docs stating otherwise. This unnecessarily confusing parameter would
be deprecated.
Thanks,
Sammy Kaye Powers
sammyk.me