3 ms·
RtlGenRandom[1] is probably the most convenient way on Windows. Does require certain definitions when including the header file for it[2] but otherwise does no
by ryuuchin 10y ago
RtlGenRandom[1] is probably the most convenient way on Windows. Does require certain definitions when including the header file for it[2] but otherwise does not require a CSP context and can generate any number of CSPRNG bytes.
[1] https://msdn.microsoft.com/en-us/library/windows/desktop/aa387694(v=vs.85).aspx https://msdn.microsoft.com/en-us/library/windows/desktop/aa3...
[2] https://boringssl.googlesource.com/boringssl/+/master/crypto/rand/windows.c#26 https://boringssl.googlesource.com/boringssl/+/master/crypto...
- cpeterso 10y agoYou're right. Calling RtlGenRandom() directly is probably the best option. I forgot that rand_s() calls RtlGenRandom(), not CryptGenRandom(). Plus both Firefox and Chrome ran into rare crashes when some bad third-party software (antivirus or malware) injects advapi32.dll hooks, causing rand_s() to crash when it tries to load advapi32.dll in order to call RtlGenRandom(). Firefox bugs: https://bugzil.la/1240589 https://bugzil.la/1240589, https://bugzil.la/1167248 https://bugzil.la/1167248, https://bugzil.la/694344 https://bugzil.la/694344 Chrome bug: https://crbug.com/348400 https://crbug.com/348400
- ryuuchin 10y agoYou can also specify the number of bytes you want with RtlGenRandom. rand_s only gives an unsigned int per call. Not a huge deal but you may be able to cut down on some function call overhead depending on how stuff gets inlined/optimized.