Predictable Randomness

Predictable randomness in C#

Description

System.Random is predictable and must not be used for security-sensitive values such as tokens, codes, session identifiers, keys, or nonces.

Potential impact

  • Token prediction, authentication bypass, or guessing session identifiers.

Remediation

Use a cryptographically secure random number generator such as RandomNumberGenerator for security-sensitive values.

Examples

Before

csharp
var token = new Random().Next();

After

csharp
var token = RandomNumberGenerator.GetBytes(32);

Explanation:

  • Before: System.Random is predictable and unsuitable for tokens, session identifiers, authentication codes, keys, nonces, passwords, or other security-sensitive values.
  • After: Use RandomNumberGenerator or another cryptographically secure source of randomness.

References