Re: unify entropy source for all php related functions
| From: | Pádraic Brady | Date: | Sat, 15 Feb 2014 11:59:34 +0000 |
| Subject: | Re: unify entropy source for all php related functions | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72628@lists.php.net to get a copy of this message | ||
Hi,
On 14 February 2014 15:30, Jakub Zelenka <bukka@php.net> wrote:
> It uses /dev/urandom for seeding PRNG. It means that it reads only 32 bytes
> (256 bits) from it. If you call openssl_random_pseudo_bytes you will get
> bytes generated by PRNG
>
>
>> - $crypto_strong will always be true on Linux (UNIX-whatever)
>>
>
> Yes. The reason is that /dev/urandom is non-blocking and you will always
> get enough entropy from it. You don't have to check the flag on Linux
> because it will be always true!
>
> The point is that OpenSSL considers /dev/urandom strong enough for seeding
> CSPRNG.
>
> Jakub
There are the three categories:
1. Non-Cryptographically Deterministic PRNG
2. Entropy Input PRNG
3. Cryptographically Secure PRNG
OpenSSL is the second. /dev/urandom is also the second. /dev/random is
the third (after a warmup period!). Something like rand() would be in
the first under the assumption that time is predictable.
Those are the technical categories anyway... In reality, you can use a
non-CSPRNG for cryptographic needs over the short term. If you can't,
it means the damn thing is broken ;). If you have something like a
long term or high value cryptographic product, you wont want to stint
on entropy and you won't want to run afoul of any future issue with
the entropy collection or mixing, and you're probably not going to
even use a machine remotely susceptible in inactivity (which may limit
the entropy sources).
Be careful of taking claims at face value where definitions are in doubt.
Paddy
--
Pádraic Brady
http://blog.astrumfutura.com
http://www.survivethedeepend.com
Zend Framework Community Review Team
Zend Framework PHP-FIG Representative