Re: Should we upgrade to a new PRNG in core?
[email protected] (Russ Allbery)
| Newsgroups | perl.perl5.porters |
|---|---|
| Organization | The Eyrie |
| Message-ID | <[email protected]> |
Aristotle Pagaltzis via perl5-porters <[email protected]> writes: > * Russ Allbery <[email protected]> [2026-01-24 04:52]: >> The primary reason to use rand() is if you need predictable (i.e., not >> actually random) random numbers for test suites, reproducible >> randomized algorithms, and other similar purposes, or as a fallback on >> platforms without /dev/random or some equivalent. > Indeed. But within those confines there are still better algorithms and > worse ones. A well-designed PRNG with useful characteristics is a good > thing to have for use cases such as sampling and numerical algorithms > that do not require actual entropy and may in fact actively disprefer > it. So “do we want a better PRNG?” is a worthwhile question even if the > answer to “should one use rand() for cryptography?” is “absolutely not” > (as you are right to point out) “– that’s not what it’s for”. Yes, completely agreed. To be clear, I have no objections to the proposal at the start of the thread. I only wanted to clarify that, somewhat by definition, replacing the internal PRNG for security reasons isn't really something that makes sense. -- #!/usr/bin/perl -- Russ Allbery, Just Another Perl Hacker $^=q;@!>~|{>krw>yn{u<$$<[~||<Juukn{=,<S~|}<Jwx}qn{<Yn{u<Qjltn{ > 0gFzD gD, 00Fz, 0,,( 0hF 0g)F/=, 0> "L$/GEIFewe{,$/ 0C$~> "@=,m,|,(e 0.), 01,pnn,y{ rw} >;,$0=q,$,,($_=$^)=~y,$/ C-~><@=\n\r,-~$:-u/ #y,d,s,(\$.),$1,gee,print