Re: Use decent entropy for uniqid($prefix, TRUE)

From: Date: Sun, 08 Jan 2017 21:08:17 +0000
Subject: Re: Use decent entropy for uniqid($prefix, TRUE)
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-97596@lists.php.net to get a copy of this message
On Mon, Jan 9, 2017 at 5:07 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > On Mon, Jan 9, 2017 at 2:29 AM, Lauri Kenttä <lauri.kentta@gmail.com> > wrote: > >> On 2017-01-07 03:15, Yasuo Ohgaki wrote: >> >>> + php_random_int(1000000000, 9999999999, &rand, 1); >>> >>> This should be >>> >>> + php_random_int(0, 9999999999, &rand, 1); >>> >> >> No, it shouldn't. That fixes none of the reported problems. You still >> have too many numbers (integer overflow) and still produce 0.abcdefgh >> instead of a.bcdefghi. >> >> If you can't fix it, maybe you shouldn't be doing it in the first place.... > > > Did you read my mail? > Please read mail again. > Anyway, I agree your way is optimal for 9 digit chars entropy. I don't care about extending entropy strength, longer length and use of non digits, for now. Are we OK with the patch Lauri proposed? Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#97596) next »