note 54925 added to function.mcrypt-create-iv

From: Date: Tue, 19 Jul 2005 20:06:41 +0000
Subject: note 54925 added to function.mcrypt-create-iv
Groups: php.notes 
Request: Send a blank email to php-notes+get-92184@lists.php.net to get a copy of this message
For some reason, on my Windows installation, MCRYPT_RAND doesn't work at all: it always gives the same IV. This is a huge problem, especially for OFB and CTR, where using the same IV destroys security. Fortunantely, it's easy to emulate the IV function using other random generators that do indeed work (such as rand() ). Here's an example: <?php function alt_mcrypt_create_iv ($size) { $iv = ''; for($i = 0; $i < $size; $i++) { $iv .= chr(rand(0,255)); } return $iv; } ?> Note that this doesn't make it "more random" in any way, it just let's you use your own favorite random function to create randomness than the quirky mcrypt_create_iv. ---- Manual Page -- http://www.php.net/manual/en/function.mcrypt-create-iv.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+54925 Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+54925&report=yes&reason=added+to+the+manual Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+54925&report=yes&reason=bad+code Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+54925&report=yes&reason=spam Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+54925&report=yes&reason=useless Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+54925&report=yes&reason=non-english Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+54925&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+54925&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#92184) next »