Re: Re: [RFC][DISCUSSION] Improve uniqid() uniqueness
| From: | Yasuo Ohgaki | Date: | Thu, 20 Oct 2016 09:44:03 +0000 |
| Subject: | Re: Re: [RFC][DISCUSSION] Improve uniqid() uniqueness | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-96510@lists.php.net to get a copy of this message | ||
Hi Kalle,
I forgot to mention one more thing.
On Thu, Oct 20, 2016 at 6:28 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> Warnings are based on following facts.
>
> uniqid(); // without entropy
>
> usleep(1) is called to get unique timestamp, but NTP can disturb and
> uniqid() can result in the same ID.
>
> uniqid('', TRUE); // with entropy
>
> It's better, but entropy is based on system timestamp and there is no
> usleep(1), so uniqid() is more sensitive to system clock adjustment by
> NTP, and uniqid() can result in the same ID.
>
> Collision is unlikely, but it not that unlikely with true CSPRNG based
> entropy. Therefore, I made warning a little strong. With CSPRNG, we
> may use more gentle warning. IMO.
Application requires unique ID under across multi process/thread
tasks, it will have more chance to have collided unique ID.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net