Re: [RFC] [DISCUSSION] Reliable user-land CSPRNG
| From: | Yasuo Ohgaki | Date: | Tue, 24 Feb 2015 22:08:30 +0000 |
| Subject: | Re: [RFC] [DISCUSSION] Reliable user-land CSPRNG | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-83705@lists.php.net to get a copy of this message | ||
Hi all,
On Wed, Feb 25, 2015 at 6:33 AM, Anthony Ferrara <ircmaxell@gmail.com>
wrote:
> On Tue, Feb 24, 2015 at 4:17 PM, Pádraic Brady <padraic.brady@gmail.com>
> wrote:
> > Hi
> >
> > On 24 February 2015 at 20:04, Anthony Ferrara <ircmaxell@gmail.com>
> wrote:
> >> If random_bytes() is harder than uniqid(), it's a non-starter.
> >
> > Technically, it will be harder than uniqid() if producing strictly
> > random bytes (if output needs to be printable/readable).
> > That's not a "bad" thing obviously!
>
> Sure. But does that indicate the need for a "random_string()" function?
>
> I don't know...
Random bytes is better. People would use it for IV or like with the
size of IV. If we use string, users loose effective bits.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net