Re: [RFC] RNG fixes

From: Date: Thu, 23 Jun 2016 13:18:33 +0000
Subject: Re: [RFC] RNG fixes
References: 1 2 3 4 5 6 7 8  Groups: php.internals 
Request: Send a blank email to internals+get-94225@lists.php.net to get a copy of this message
On 6/22/16, 5:19 PM, "Nikita Popov" <nikita.ppv@gmail.com> wrote: >I haven't been following this thread, just jumping in to comment on this >point. My suggestion to deprecate rand() was motivated by the fact that >rand() produces extremely low quality random numbers on Windows, while at >the same time having the name people are most likely to try first if they >want to have a random number. It's a bad state of things if there's a >rand() and an mt_rand() function and the latter is preferable in *all* >situations, while the former is more likely to be used. However, this >concern is completely alleviated by aliasing rand() to mt_rand(). If we >do this, I see no reason to deprecate rand(), at least in the short term. Alternatively, if you fix rand() by making *it* the new, fast, platform-independent RNG (e.g. Xoroshiro128+) and leave mt_rand() alone then: 1. The "bad state of things" you described is resolved. 2. The various complaints about mt_rand() become irrelevant because rand() will be preferable in *all* situations (except security and backwards compat). Tom

« previous php.internals (#94225) next »