note 25004 rejected from function.mt-srand by jmcastagnetto
| From: | jmcastagnetto@php.net | Date: | Sun, 08 Sep 2002 00:03:11 +0000 |
| Subject: | note 25004 rejected from function.mt-srand by jmcastagnetto | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-36324@lists.php.net to get a copy of this message | ||
mt_srand() and srand() are wrong: one should only use them to create reproducible pseudo-random
sequences, but in a limited set of choices.
A make_seed() function will not help solve this problem, because of the limited range of the seed.
It would have been better that srand() and mt_rand() accept an entropy string of any length, to
initialize its internal state.
Isn't it possible to imagine a randfeed() and mt_randfeed() call, to send this data as a less
limited string seed, where we can collect various sources of entropy such as microtime(),
getmypid(), diskfreespace() if accessible, the request string, cookies, remote user name if working
in a session, form data, ...
The feed call could be used several times and could be used with arrays such as $_GET, $_POST, ...