Re: Use decent entropy for uniqid($prefix, TRUE)
| From: | Yasuo Ohgaki | Date: | Sat, 21 Jan 2017 02:25:45 +0000 |
| Subject: | Re: Use decent entropy for uniqid($prefix, TRUE) | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-97908@lists.php.net to get a copy of this message | ||
Hi Niklas,
On Fri, Jan 20, 2017 at 1:07 AM, Niklas Keller <me@kelunik.com> wrote:
> has this been committed? It's just the same BC issue as seeding mt_rand
> with a CSPRNG by default.
Not yet.
I really don't see any pros for caring about failing CSPRNG and fallback to
weak behavior.
1) BC is extremely unlikely. Basically, no BC on healthy hardware/OS.
2) Then things failed, programs should fail properly. i.e. Shouldn't
fallback to weaker/problematic code.
Broken CSPRNG is like BUS error, i.e. hardware error, why should we care so
much about it?
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net