Re: Re: [RFC][DISCUSSION] Improve uniqid() uniqueness

From: Date: Thu, 20 Oct 2016 09:44:03 +0000
Subject: Re: Re: [RFC][DISCUSSION] Improve uniqid() uniqueness
References: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20  Groups: php.internals 
Request: Send a blank email to internals+get-96510@lists.php.net to get a copy of this message
Hi Kalle, I forgot to mention one more thing. On Thu, Oct 20, 2016 at 6:28 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > Warnings are based on following facts. > > uniqid(); // without entropy > > usleep(1) is called to get unique timestamp, but NTP can disturb and > uniqid() can result in the same ID. > > uniqid('', TRUE); // with entropy > > It's better, but entropy is based on system timestamp and there is no > usleep(1), so uniqid() is more sensitive to system clock adjustment by > NTP, and uniqid() can result in the same ID. > > Collision is unlikely, but it not that unlikely with true CSPRNG based > entropy. Therefore, I made warning a little strong. With CSPRNG, we > may use more gentle warning. IMO. Application requires unique ID under across multi process/thread tasks, it will have more chance to have collided unique ID. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#96510) next »