5 ms·
Not impossible, just more difficult to guess. "Security through obscurity" isn't really good enough.
by bsuvc 1y ago
Not impossible, just more difficult to guess.
"Security through obscurity" isn't really good enough.
- tyre 1y agoYes and… UUIDs aren’t “just more difficult to guess.” They are inconceivably harder to guess. > Put another way, one would need to generate 1 billion v4 UUIDs per second for 85 years to have a 50% chance of a single collision.
- 0cf8612b2e1e 1y agoThe security is that your server will crash from overload long before someone can guess the ids.
- zarzavat 1y agoYou are both right. UUIDs, if randomly generated from a CSPRNG are impossible to guess. But not all UUIDs are generated from a secure RNG, or use randomness at all.
- xeromal 1y agoI may be a dingleberry but who doesn't use uuidv4 for everything?
- hardwaresofton 1y agoUUIDv7 indexes better in databases
- cobbal 1y agoUUIDv4 may or may not use a cryptographically secure random number generator. Python's UUID library, for example, falls back to the insecure 'random' module. Given a handful of outputs, it's possible to predict future ones.
- 0cf8612b2e1e 1y agoGasp! I had no idea about the Python implementation. Not that I do anything where it would matter (just need a random id), but for an already slow language, I would prefer the safer default.
- maple3142 1y agoFor python specifically, the uuid4 function does use the randomness from os.urandom, which is supposed to be cryptographically random on most platforms.
- shakna 1y agoUh... Come again? def uuid4(): """Generate a random UUID.""" return UUID(bytes=os.urandom(16), version=4) https://github.com/python/cpython/blob/3.13/Lib/uuid.py https://github.com/python/cpython/blob/3.13/Lib/uuid.py
- sergeyprokhoren 1y ago[dead]
- cobbal 1y agoNice. Looks like I was looking at an old version of the file. https://github.com/python/cpython/commit/09ba98436444d2a4e11a5d3801773bb20441a1ac https://github.com/python/cpython/commit/09ba98436444d2a4e11...
- shakna 1y agoYeah, Python went through a big shakeup around secure randomness when they put together the "secrets" library, around a decade ago. A lot of that also got backported on most OSs. So there really shouldn't be anyone using that today, thankfully.
- hardwaresofton 1y agoYes, you are technically right -- I should have said "functionally impossible". It's not actually impossible, but close enough for the average random onlooker.