Re: Re: Improving mt_rand() seed
| From: | Leigh | Date: | Wed, 18 Jan 2017 09:20:45 +0000 |
| Subject: | Re: Re: Improving mt_rand() seed | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-97852@lists.php.net to get a copy of this message | ||
On Wed, 18 Jan 2017 at 06:05 Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> It could be. I haven't read and research MT rand initialization code
> carefully yet.
I have, it stretches 4 bytes of seed material into 624 * 4 bytes of
material. There are only 2^32 possible initial states from direct seeding.
After the state has been consumed it does a "twist"-pass on the existing
state, this is where the "^19937-1 period comes from.
I would recommend taking 4 bytes from php_random_bytes_silent() cast to
uint32_t and passed to php_mt_srand(), if php_random_bytes_silent() fails
fall back to the original seeding generation mechanism (it is unlikely an
adversary can know which method was used)