note 71075 added to function.mt-rand
| From: | Chris at osu1 dot php dot net | Date: | Fri, 10 Nov 2006 19:35:33 +0000 |
| Subject: | note 71075 added to function.mt-rand | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-119593@lists.php.net to get a copy of this message | ||
>Running the output of Mersenne Twister through an unkeyed >secure hash is NOT a good way to
>make it secure, because it'll >still have a relatively small internal state which, if
>recovered, >would allow reproduction of the keystream. A better idea >would be to encrypt the
>output with a keyed encryption >algorithm - but if you were going to do that, you wouldn't
>>need a psuedorandom number generator at all, because a >counter would be just as good.
Not true. Mersenne Twister has an ENORMOUS amount of internal state - 4992 bits, bigger than
practically any cipher's key length. The point of a secure random number generator is that you
cannot predict future outputs based on past OUTPUTS, which is why a hash is applied. Clearly you can
predict the future output of any pseudorandom number generator if you can acquire the internal state
- a better algorithm will never solve this problem. If you use keyed encryption, recovering the key
allows you to predict future outputs.
----
Server IP: 66.207.199.35
Probable Submitter: 128.189.253.192
----
Manual Page -- http://www.php.net/manual/en/function.mt-rand.php
Edit -- https://master.php.net/note/edit/71075
Del: integrated -- https://master.php.net/note/delete/71075/integrated
Del: useless -- https://master.php.net/note/delete/71075/useless
Del: bad code -- https://master.php.net/note/delete/71075/bad+code
Del: spam -- https://master.php.net/note/delete/71075/spam
Del: non-english -- https://master.php.net/note/delete/71075/non-english
Del: in docs -- https://master.php.net/note/delete/71075/in+docs
Del: other reasons-- https://master.php.net/note/delete/71075
Reject -- https://master.php.net/note/reject/71075
Search -- https://master.php.net/manage/user-notes.php