{"id":39853,"date":"2004-04-12T07:00:00","date_gmt":"2004-04-12T07:00:00","guid":{"rendered":"https:\/\/blogs.msdn.microsoft.com\/oldnewthing\/2004\/04\/12\/the-random-number-seed-can-be-the-weakest-link\/"},"modified":"2004-04-12T07:00:00","modified_gmt":"2004-04-12T07:00:00","slug":"the-random-number-seed-can-be-the-weakest-link","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/oldnewthing\/20040412-00\/?p=39853","title":{"rendered":"The random number seed can be the weakest link"},"content":{"rendered":"<p>Random number generation is hard.  That&#8217;s why you should leave it to the experts.\n  But even if you choose a good random number generator,  you still have to seed it properly.  <a href=\"http:\/\/www.cs.berkeley.edu\/~daw\/papers\/ddj-netscape.html\">  The best random number generator in the world isn&#8217;t  very useful if people can guess the seed<\/a>.  That&#8217;s why  <a href=\"http:\/\/weblogs.asp.net\/gstemp\/archive\/2004\/02\/23\/78434.aspx\">  seeding the random number generator with the current time  is not very secure<\/a>;  it&#8217;s not hard to guess the current time!\n  So it&#8217;s important to throw something unguessable into the seed.  As the above paper notes, just the time and process id are not good  enough.<\/p>\n<p>  So what should you do?  Don&#8217;t ask me; I&#8217;m not a cryptography expert.  <a href=\"http:\/\/www.cs.berkeley.edu\/~daw\/rnd\/\">  Here are some suggestions from other people<\/a>.  Maybe some of them are good, maybe not.  <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Random number generation is hard. That&#8217;s why you should leave it to the experts. But even if you choose a good random number generator, you still have to seed it properly. The best random number generator in the world isn&#8217;t very useful if people can guess the seed. That&#8217;s why seeding the random number generator [&hellip;]<\/p>\n","protected":false},"author":1069,"featured_media":111744,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[25],"class_list":["post-39853","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-oldnewthing","tag-code"],"acf":[],"blog_post_summary":"<p>Random number generation is hard. That&#8217;s why you should leave it to the experts. But even if you choose a good random number generator, you still have to seed it properly. The best random number generator in the world isn&#8217;t very useful if people can guess the seed. That&#8217;s why seeding the random number generator [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/39853","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/users\/1069"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/comments?post=39853"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/39853\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media\/111744"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media?parent=39853"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/categories?post=39853"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/tags?post=39853"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}