CryptographicallySecureRandomness
error on by defaultGroup: Security · PhpStorm name: CryptographicallySecureRandomnessInspection
openssl_random_pseudo_bytes() and mcrypt_create_iv() can silently fall back to weak sources or fail (returning false) and their strength depends on optional arguments. Point out missing strength arguments, unverified results and weak sources, and suggest random_bytes() on PHP 7+.
Example
php
<?php
class Tokens
{
public function salt()
{
$raw = openssl_random_pseudo_bytes(16);
if (false === $raw) {
throw new RuntimeException('no entropy');
}
return $raw;
}
public function nonce()
{
$n = mcrypt_create_iv(24, MCRYPT_RAND);
return $n !== false ? $n : null;
}
public function pepper()
{
return openssl_random_pseudo_bytes(8, $strong);
}
public function seed()
{
$bytes = @openssl_random_pseudo_bytes(32, $good);
if (!$bytes || !$good) {
return null;
}
return $bytes;
}
}Reported:
- line 6: Pass a second argument to learn whether a strong algorithm was used.
- line 15: Prefer MCRYPT_DEV_RANDOM as the entropy source.
- line 21: The generated bytes may be false; check the result.
- line 21: The strength flag may be false; check it.
Configure
In custos.json:
json
{
"rules": {
"CryptographicallySecureRandomness": {
"enabled": false
}
}
}Suppress
Before the statement or declaration (or the first statement of the file), either of:
php
// @custos-ignore CryptographicallySecureRandomness
/**
* @noinspection CryptographicallySecureRandomnessInspection
*/