EncryptionInitializationVectorRandomness
error on by defaultGroup: Security · PhpStorm name: EncryptionInitializationVectorRandomnessInspection
An encryption initialization vector must be unpredictable. When the IV passed to openssl_encrypt() / mcrypt_encrypt() can be traced to something other than a cryptographic random generator (a literal, mt_rand(), …), report it.
Example
php
<?php
class Box
{
const SALT = 'static-iv';
private $nonce = 'fixed';
private $fresh;
public function lock($msg, $pass, $iv = '0000')
{
$iv = uniqid();
$out = openssl_encrypt($msg, 'aes-256-cbc', $pass, 0, $iv);
$old = mcrypt_encrypt('rijndael-128', $pass, $msg, 'cbc', self::SALT);
$this->nonce = rand();
$alt = openssl_encrypt($msg, 'aes-256-cbc', $pass, 0, $this->nonce);
$this->fresh = random_bytes(16);
$ok1 = openssl_encrypt($msg, 'aes-256-cbc', $pass, 0, $this->fresh);
$ok2 = openssl_encrypt($msg, 'aes-256-cbc', $pass, 0, $this->makeIv());
$ok3 = openssl_encrypt($msg, 'aes-256-cbc', $pass);
return [$out, $old, $alt, $ok1, $ok2, $ok3];
}
private function makeIv()
{
return openssl_random_pseudo_bytes(16);
}
}Reported:
- line 11: Generate the IV with openssl_random_pseudo_bytes(); it may come from: '0000', uniqid().
- line 12: Generate the IV with mcrypt_create_iv(); it may come from: 'static-iv'.
- line 15: Generate the IV with openssl_random_pseudo_bytes(); it may come from: 'fixed', rand().
Configure
In custos.json:
json
{
"rules": {
"EncryptionInitializationVectorRandomness": {
"enabled": false
}
}
}Suppress
Before the statement or declaration (or the first statement of the file), either of:
php
// @custos-ignore EncryptionInitializationVectorRandomness
/**
* @noinspection EncryptionInitializationVectorRandomnessInspection
*/