Re: unify entropy source for all php related functions
| From: | Pierre Joye | Date: | Fri, 14 Feb 2014 15:41:04 +0000 |
| Subject: | Re: unify entropy source for all php related functions | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72603@lists.php.net to get a copy of this message | ||
On Feb 14, 2014 10:30 PM, "Jakub Zelenka" <bukka@php.net> wrote:
> The point is that OpenSSL considers /dev/urandom strong enough for
seeding CSPRNG.
The point here is about whether /Dev/urandom is cs or not. It is not. It
may be (on recent updated systems) enough to be used as seed but not to
actually generate cs random data.
Also it is important to keep mind that openssl does more than simply read
from urandom or random to generate data. That's outside the scope of what
is proposed here.
Cheers,
Pierre