Re: [RFC] [Discussion] PHP 8.3 deprecations
| From: | Tim Düsterhus | Date: | Tue, 30 May 2023 16:03:44 +0000 |
| Subject: | Re: [RFC] [Discussion] PHP 8.3 deprecations | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-120461@lists.php.net to get a copy of this message | ||
Hi
On 5/30/23 17:52, Go Kudo wrote:
It should be deprecated with PHP 8.4 at the earliest to give folks at least Indeed, I agree thatAs the function is not seedable in userland, we do not need to preserve a specific sequence or behavior. Therefore it should be possible to replace the seeding to make use of the CSPRNG and fall back to the old and insecure seeding if the CSPRNG fails. For the same reason, the global state is also less of a problem compared to mt_rand() and friends.lcg_value()should be deprecated at least in PHP 8.4. However,lcg_value()remains a dangerous function. It still has a weak initial seeding problem (PID, time), not to mention global state. This is extremely dangerous for workloads on containers where PIDs tend to be fixed. Perhaps this should be documented at the time of PHP 8.3 release.
Because of the above, I have removed my lcg_value() deprecation entry
from the RFC. Thanks!
Thanks!
Best regards
Tim Düsterhus