Skip to content

CryptographicallySecureRandomness ​

error on by default

Group: Security · PhpStorm name: CryptographicallySecureRandomnessInspection

openssl_random_pseudo_bytes() and mcrypt_create_iv() can silently fall back to weak sources or fail (returning false) and their strength depends on optional arguments. Point out missing strength arguments, unverified results and weak sources, and suggest random_bytes() on PHP 7+.

Example ​

php
<?php
class Tokens
{
    public function salt()
    {
        $raw = openssl_random_pseudo_bytes(16);
        if (false === $raw) {
            throw new RuntimeException('no entropy');
        }
        return $raw;
    }

    public function nonce()
    {
        $n = mcrypt_create_iv(24, MCRYPT_RAND);
        return $n !== false ? $n : null;
    }

    public function pepper()
    {
        return openssl_random_pseudo_bytes(8, $strong);
    }

    public function seed()
    {
        $bytes = @openssl_random_pseudo_bytes(32, $good);
        if (!$bytes || !$good) {
            return null;
        }
        return $bytes;
    }
}

Reported:

  • line 6: Pass a second argument to learn whether a strong algorithm was used.
  • line 15: Prefer MCRYPT_DEV_RANDOM as the entropy source.
  • line 21: The generated bytes may be false; check the result.
  • line 21: The strength flag may be false; check it.

Configure ​

In custos.json:

json
{
  "rules": {
    "CryptographicallySecureRandomness": {
      "enabled": false
    }
  }
}

Suppress ​

Before the statement or declaration (or the first statement of the file), either of:

php
// @custos-ignore CryptographicallySecureRandomness

/**
 * @noinspection CryptographicallySecureRandomnessInspection
 */

Released under the MIT License. Rule catalogue modelled on Php Inspections (EA Extended); independent clean-room implementation.