note 25004 rejected from function.mt-srand by jmcastagnetto

From: Date: Sun, 08 Sep 2002 00:03:11 +0000
Subject: note 25004 rejected from function.mt-srand by jmcastagnetto
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-36324@lists.php.net to get a copy of this message
mt_srand() and srand() are wrong: one should only use them to create reproducible pseudo-random sequences, but in a limited set of choices. A make_seed() function will not help solve this problem, because of the limited range of the seed. It would have been better that srand() and mt_rand() accept an entropy string of any length, to initialize its internal state. Isn't it possible to imagine a randfeed() and mt_randfeed() call, to send this data as a less limited string seed, where we can collect various sources of entropy such as microtime(), getmypid(), diskfreespace() if accessible, the request string, cookies, remote user name if working in a session, form data, ... The feed call could be used several times and could be used with arrays such as $_GET, $_POST, ...

« previous php.notes (#36324) next »