Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Improve quality of generated seed, avoid potential security pitfall
* Try to use random_bytes() first if it's available * Do not include the server parameters in the generated seed, as they might contain sensitive data As all current usages of getRandomSeed() directly hash the seed, there should be no BC breaking changes. The main source of entropy is more than enough on its own if random_bytes() or openssl_random_pseudo_bytes() are available.
- Loading branch information