Re: Re: Improving mt_rand() seed
| From: | Yasuo Ohgaki | Date: | Thu, 02 Feb 2017 23:36:26 +0000 |
| Subject: | Re: Re: Improving mt_rand() seed | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-98129@lists.php.net to get a copy of this message | ||
Hi Niklas,
On Thu, Feb 2, 2017 at 11:05 PM, Niklas Keller <me@kelunik.com> wrote:
> 2017-02-02 14:24 GMT+01:00 Christoph M. Becker <cmbecker69@gmx.de>:
>
>> On 02.02.2017 at 12:51, Yasuo Ohgaki wrote:
>>
>> > Although users must never do this, but there are codes that generate
>> random
>> > password/access key by mt_rand().
>>
>> There is also code that stores clear text passwords. How would you
>> prevent that?
>>
>> IMHO, if users don't care to read the docs[1], it's their fault, and we
>> shouldn't waste our time to fix their bugs.
>
>
> While the documentation states that, it can still be improved.
>
> I've just submitted a patch, you can find the diff here:
> https://gist.github.com/kelunik/bb534d4c4ede160d97ef17014052052a$*�[*ofs¿ºÐ
> ¡" (linking
> patches via edit.php.net doesn't really work, it just links to the newest
> patch of a file and will break once merged).
>
Nice patch! I'm OK with your patch.
Currently, mt_rand() value is affected by srand() in PHP 7.1.
It may be described, but I think there will be new PRNG state for
rand()/srand() at least, hopefully soon.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net