Re: [RFC] [DISCUSSION] Reliable user-land CSPRNG
| From: | Stanislav Malyshev | Date: | Thu, 26 Feb 2015 08:48:29 +0000 |
| Subject: | Re: [RFC] [DISCUSSION] Reliable user-land CSPRNG | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-83874@lists.php.net to get a copy of this message | ||
Hi!
> I'm cool with that idea but I also think it should be spelled out like `
> random_crypto_*()
as Pierre suggests. I like
> secure_random_bytes()` but
> that's because it's what Ruby names their CSPRNG. :)
The custom is that the first word names the function group (yes, I know
old functions do not follow it, but this is new one). Unless we're going
to introduce a group of functions called secure_*, random_* is a natural
choice. I would be careful with using words like "secure", "crypto" etc.
in general because they may be easily misunderstood - something like
random_bytes() would do as well I think.
--
Stas Malyshev
smalyshev@gmail.com