note 71075 added to function.mt-rand

From: Date: Fri, 10 Nov 2006 19:35:33 +0000
Subject: note 71075 added to function.mt-rand
Groups: php.notes 
Request: Send a blank email to php-notes+get-119593@lists.php.net to get a copy of this message
>Running the output of Mersenne Twister through an unkeyed >secure hash is NOT a good way to >make it secure, because it'll >still have a relatively small internal state which, if >recovered, >would allow reproduction of the keystream. A better idea >would be to encrypt the >output with a keyed encryption >algorithm - but if you were going to do that, you wouldn't >>need a psuedorandom number generator at all, because a >counter would be just as good. Not true. Mersenne Twister has an ENORMOUS amount of internal state - 4992 bits, bigger than practically any cipher's key length. The point of a secure random number generator is that you cannot predict future outputs based on past OUTPUTS, which is why a hash is applied. Clearly you can predict the future output of any pseudorandom number generator if you can acquire the internal state - a better algorithm will never solve this problem. If you use keyed encryption, recovering the key allows you to predict future outputs. ---- Server IP: 66.207.199.35 Probable Submitter: 128.189.253.192 ---- Manual Page -- http://www.php.net/manual/en/function.mt-rand.php Edit -- https://master.php.net/note/edit/71075 Del: integrated -- https://master.php.net/note/delete/71075/integrated Del: useless -- https://master.php.net/note/delete/71075/useless Del: bad code -- https://master.php.net/note/delete/71075/bad+code Del: spam -- https://master.php.net/note/delete/71075/spam Del: non-english -- https://master.php.net/note/delete/71075/non-english Del: in docs -- https://master.php.net/note/delete/71075/in+docs Del: other reasons-- https://master.php.net/note/delete/71075 Reject -- https://master.php.net/note/reject/71075 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#119593) next »