Description
System.Random is predictable and must not be used for security-sensitive values such as tokens, codes, session identifiers, keys, or nonces.
Potential impact
- Token prediction, authentication bypass, or guessing session identifiers.
Remediation
Use a cryptographically secure random number generator such as RandomNumberGenerator for security-sensitive values.
Examples
Before
csharp
var token = new Random().Next();
After
csharp
var token = RandomNumberGenerator.GetBytes(32);
Explanation:
- Before:
System.Randomis predictable and unsuitable for tokens, session identifiers, authentication codes, keys, nonces, passwords, or other security-sensitive values. - After: Use
RandomNumberGeneratoror another cryptographically secure source of randomness.