note 71075 deleted from function.mt-rand by cmb
| From: | cmb@php.net | Date: | Sun, 19 Jan 2020 08:35:53 +0000 |
| Subject: | note 71075 deleted from function.mt-rand by cmb | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-213912@lists.php.net to get a copy of this message | ||
Note Submitter: Chris
----
>Running the output of Mersenne Twister through an unkeyed >secure hash is NOT a good way to
>make it secure, because it'll >still have a relatively small internal state which, if
>recovered, >would allow reproduction of the keystream. A better idea >would be to encrypt the
>output with a keyed encryption >algorithm - but if you were going to do that, you wouldn't
>>need a psuedorandom number generator at all, because a >counter would be just as good.
Not true. Mersenne Twister has an ENORMOUS amount of internal state - 4992 bits, bigger than
practically any cipher's key length. The point of a secure random number generator is that you
cannot predict future outputs based on past OUTPUTS, which is why a hash is applied. Clearly you can
predict the future output of any pseudorandom number generator if you can acquire the internal state
- a better algorithm will never solve this problem. If you use keyed encryption, recovering the key
allows you to predict future outputs.