Pseudorandom number generators (PRNGs) produce sequences that only approximate true randomness and are not suitable for security-sensitive contexts.
When software generates predictable values in a context requiring unpredictability, an attacker who knows or can guess the internal state of the PRNG may predict the next value that will be generated. The rule flags the use of non-cryptographic PRNGs in contexts where a cryptographically secure pseudorandom number generator (CSPRNG) is required, such as generating encryption keys, tokens, or other secret values.
As the rand() and mt_rand() functions are not CSPRNGs, they should not be used for security-critical applications or for
protecting sensitive data.
If an attacker can predict the values generated by a PRNG, they may be able to guess session tokens, encryption keys, password reset links, or other secrets, leading to unauthorized access or impersonation.
Using a non-cryptographic PRNG to generate keys or initialization vectors weakens the security of the cryptographic scheme, potentially making it trivially breakable.
Use functions which rely on a cryptographically secure pseudo random number generator (CSPRNG) such as random_int(),
random_bytes(), or openssl_random_pseudo_bytes(). When using openssl_random_pseudo_bytes(), provide and check
the crypto_strong parameter.
Use a cryptographically secure pseudorandom number generator (CSPRNG) instead of a non-cryptographic PRNG.
$random = rand(); // Noncompliant $random2 = mt_rand(0, 99); // Noncompliant
$randomInt = random_int(0,99);