Re: [RFC] [DISCUSSION] Reliable user-land CSPRNG

From: Date: Tue, 24 Feb 2015 22:08:30 +0000
Subject: Re: [RFC] [DISCUSSION] Reliable user-land CSPRNG
References: 1 2 3 4 5 6 7  Groups: php.internals 
Request: Send a blank email to internals+get-83705@lists.php.net to get a copy of this message
Hi all, On Wed, Feb 25, 2015 at 6:33 AM, Anthony Ferrara <ircmaxell@gmail.com> wrote: > On Tue, Feb 24, 2015 at 4:17 PM, Pádraic Brady <padraic.brady@gmail.com> > wrote: > > Hi > > > > On 24 February 2015 at 20:04, Anthony Ferrara <ircmaxell@gmail.com> > wrote: > >> If random_bytes() is harder than uniqid(), it's a non-starter. > > > > Technically, it will be harder than uniqid() if producing strictly > > random bytes (if output needs to be printable/readable). > > That's not a "bad" thing obviously! > > Sure. But does that indicate the need for a "random_string()" function? > > I don't know... Random bytes is better. People would use it for IV or like with the size of IV. If we use string, users loose effective bits. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#83705) next »