4 ms·
Please don't use arc4random* for cryptographic purposes. RC4 is broken -- there are practical attacks against it. It's fine for non-secure purposes though (eg.
by nshepperd 10y ago
Please don't use arc4random* for cryptographic purposes. RC4 is broken -- there are practical attacks against it. It's fine for non-secure purposes though (eg. monte carlo simulation).
- tossedaway334 10y agoarc4random uses chacha20 on openBSD now, has for several years, OSX and FreeBSD are yet to update...
- eddieh 10y agoThe macOS Sierra man page says it uses the NIST-approved AES cipher and will be replaced as the techniques advance.
- eddieh 10y agoThe 'arc4' no longer refers to RC4 on macOS/iOS and OpenBSD. On those systems 'arc4random' is playfully a bacronym for "A Replacement Call for Random". The new arc4random* implementation will now be replaced as cryptographic techniques advance. It appears the Apple and OpenBSD implementations use the getentropy syscall and then add additional entropy mixing.
- gbrown_ 10y agoYup, OpenBSD have even changed calls to other entropy sources to returning strong random by default from arc4random. http://marc.info/?l=openbsd-cvs&m=141807513728073&w=2 http://marc.info/?l=openbsd-cvs&m=141807513728073&w=2
- arthur2e5 10y agolibbsd is also using getentropy: https://cgit.freedesktop.org/libbsd/tree/src/arc4random.c https://cgit.freedesktop.org/libbsd/tree/src/arc4random.c