5 ms·
Perl's rand() is not a great way to generate values that should be unpredictable. It is seeded with only 4 bytes from /dev/urandom and is an LFSR like rand(3).
by hoytech 8y ago
Perl's rand() is not a great way to generate values that should be unpredictable. It is seeded with only 4 bytes from /dev/urandom and is an LFSR like rand(3).
The consequence is that the range of possible passwords is probably smaller than was intended, and furthermore seeing previous passwords (or the random MAC) may help in predicting passwords. Of course without seeing their entire setup it's hard to say to what extent that is the case here.
This module may be useful (it even uses the same alphabet by default): https://metacpan.org/pod/Session::Token https://metacpan.org/pod/Session::Token
- dchest 8y agoWas thinking the same. Then remembered that OpenBSD's rand(3) actually returns result from arc4random() now. Then went to check and it seemed like Perl doesn't actually use rand(3) from libc? At least Perl's srand(N) and then rand() returned deterministic results, which shouldn't happen if it was using rand(3)...
- hoytech 8y agoYes good point. I was careful not to say that perl actually uses rand(3) because I think it may not for portability reasons. Also, I think this may have changed at some point so might be different depending on perl version.
- notaplumber 8y agoOpenBSD's carrying some local patches, Perl rand appears to be using the libc drand48(3) on OpenBSD, which uses arc4random_buf(3) internally, unless Perl srand is called, then it uses srand48_deterministic(3)? Not sure precisely as it's also using arc4random(3) directly to seed something. This is slightly different from how it's handled outside the Perl software ecosystem, as all the srand* functions effectively became nops on OpenBSD in favour of strong random numbers, and userland ports had to be patched to use the deterministic variants if needed. I guess that would be hard with things like CPAN. https://github.com/openbsd/src/commit/2e109fb9e8c0dc273648ddbc62f0a74abf9e098d#diff-b1d655ef1da257a3f4c33327fb83bd0dR20776 https://github.com/openbsd/src/commit/2e109fb9e8c0dc273648dd... https://github.com/openbsd/src/commit/2e109fb9e8c0dc273648ddbc62f0a74abf9e098d#diff-6f239a14c0c4e792da78a0310d16d9a1R4652 https://github.com/openbsd/src/commit/2e109fb9e8c0dc273648dd... https://github.com/openbsd/src/commit/2e109fb9e8c0dc273648ddbc62f0a74abf9e098d#diff-9dc22d2e9511b13cd64378f8671179edR3133 https://github.com/openbsd/src/commit/2e109fb9e8c0dc273648dd... Looks like upstream Perl also uses drand48 from FreeBSD, with its own internal RNG. But I guess this can be overridden with build options. I'd imagine something like pwgen would be better, but I doubt it matters here.
- hoytech 8y agoThank you for the details. I agree none of this probably matters much for their use-case.