php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #68959 limit rand() function
Submitted: 2015-01-30 09:38 UTC Modified: 2015-01-30 20:46 UTC
From: peter dot mlich at volny dot cz Assigned:
Status: Not a bug Package: *General Issues
PHP Version: 5.5.21 OS: win
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: peter dot mlich at volny dot cz
New email:
PHP Version: OS:

 

 [2015-01-30 09:38 UTC] peter dot mlich at volny dot cz
Description:
------------
After about 32000 function rand() repeating number (or zero?) as pattern. Array can be easy compressed by gzip.

If you understand about compression, this is critical bug. I test array with 10.000 numbers, gzip compress to 33%. Other script with no rand() with read from file compress about 100.5% (my compress script about 95%).
I cant use random data generator, if repeating as pattern which can easy compress with php-gzip.

php 5.3.5, wamp server 2.1
php 5.5.12, wamp server 2.5

Test script:
---------------
$max = 32000;
$max = 100000;
$arr = array();
for ($i=0;$i<$max;$i++)
	{
	$arr[$i] = rand(0,255);
	}
return $arr;



Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2015-01-30 20:22 UTC] nikic@php.net
-Status: Open +Status: Not a bug
 [2015-01-30 20:22 UTC] nikic@php.net
rand() exposes the libc rand source and Windows is notable for providing a very weak linear congruential generator. If you want to get stronger random numbers, use mt_rand(), which is based on MT19937. Note that they aren't cryptographic in any case.
 [2015-01-30 20:46 UTC] ab@php.net
Yeah, also it works much better when using srand() before, like maybe

srand(microtime(1)*1000000);

But really depends on which exact windows, before 8 one might need to produce a better seed.

Cheers.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Thu Oct 08 00:00:02 2026 UTC