note 54925 added to function.mcrypt-create-iv
| From: | edwardzyang at thewritingpot dot com | Date: | Tue, 19 Jul 2005 20:06:41 +0000 |
| Subject: | note 54925 added to function.mcrypt-create-iv | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-92184@lists.php.net to get a copy of this message | ||
For some reason, on my Windows installation, MCRYPT_RAND doesn't work at all: it always gives
the same IV. This is a huge problem, especially for OFB and CTR, where using the same IV destroys
security.
Fortunantely, it's easy to emulate the IV function using other random generators that do indeed
work (such as rand() ). Here's an example:
<?php
function alt_mcrypt_create_iv ($size) {
$iv = '';
for($i = 0; $i < $size; $i++) {
$iv .= chr(rand(0,255));
}
return $iv;
}
?>
Note that this doesn't make it "more random" in any way, it just let's you use
your own favorite random function to create randomness than the quirky mcrypt_create_iv.
----
Manual Page -- http://www.php.net/manual/en/function.mcrypt-create-iv.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+54925
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+54925&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+54925&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+54925&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+54925&report=yes&reason=useless
Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+54925&report=yes&reason=non-english
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+54925&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+54925&report=yes
Search -- http://master.php.net/manage/user-notes.php