3 ms·
It's both. The strpos() check is what you're describing, but openssl_random_pseudo_bytes() accepts an optional second by-reference argument and sets it to true
by CiPHPerCoder 4y ago
It's both.
The strpos() check is what you're describing, but openssl_random_pseudo_bytes() accepts an optional second by-reference argument and sets it to true or false depending on the behavior of RAND_pseudo_bytes().
https://www.php.net/openssl_random_pseudo_bytes https://www.php.net/openssl_random_pseudo_bytes
This function also isn't fork-safe in PHP, and has caused RNG collisions before:
https://github.com/ramsey/uuid/issues/80 https://github.com/ramsey/uuid/issues/80
Consequently, I advise against using this function entirely. random_bytes() is better in every way.
- 3np 4y agoIf I get that part right, it would generally have the same return value throughout the lifetime of a process. So in the off-chance that it does trigger, it gets stuck in an infinite loop.
- CiPHPerCoder 4y agoCorrect. The strpos() check just prevents the IV from containing ::