note 25004 added to function.mt-srand
| From: | php-general at lists dot php dot net | Date: | Sat, 07 Sep 2002 16:21:44 +0000 |
| Subject: | note 25004 added to function.mt-srand | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-36303@lists.php.net to get a copy of this message | ||
mt_srand() and srand() are wrong: one should only use them to create reproducible pseudo-random
sequences, but in a limited set of choices.
A make_seed() function will not help solve this problem, because of the limited range of the seed.
It would have been better that srand() and mt_rand() accept an entropy string of any length, to
initialize its internal state.
Isn't it possible to imagine a randfeed() and mt_randfeed() call, to send this data as a less
limited string seed, where we can collect various sources of entropy such as microtime(),
getmypid(), diskfreespace() if accessible, the request string, cookies, remote user name if working
in a session, form data, ...
The feed call could be used several times and could be used with arrays such as $_GET, $_POST, ...
--
http://www.php.net/manual/en/function.mt-srand.php
http://master.php.net/manage/user-notes.php?action=edit+25004
http://master.php.net/manage/user-notes.php?action=delete+25004
http://master.php.net/manage/user-notes.php?action=reject+25004