Re: Re: Security changes in PHP 7
| From: | Daniel Lowrey | Date: | Sun, 08 Feb 2015 17:52:56 +0000 |
| Subject: | Re: Re: Security changes in PHP 7 | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-82155@lists.php.net to get a copy of this message | ||
On Sun, Feb 8, 2015 at 12:11 PM, Tom Worster <fsb@thefsb.org> wrote:
>
> Thanks Damien and Daniel for the info.
>
> I am not concerned about running out of entropy. I am concerned about
> userspace RNGs such as OpenSSL
>
> http://sockpuppet.org/blog/2014/02/25/safely-generate-random-numbers/
Just to be clear (as Damien also mentioned): openssl is not a userspace
RNG. It uses the underlying system-specific resources. If your system's RNG
is good enough (/dev/[u]random in nix-like systems) for you,
openssl_random_pseudo_bytes() is good enough for you.