This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 30 · Jul 21 – 27, 2025

crypto: ignore rand io.Reader where behavior is not specified

Worth knowingstdlib

What changed
Most crypto APIs will ignore the io.Reader parameter for randomness and always use the system random source (crypto/internal/sysrand.Read). A GODEBUG=cryptocustomrand=1 flag restores the old behavior. A new testing/cryptotest package will allow deterministic randomness in tests.
Production impact
The source does not say.
Try it
Compile a program that calls rsa.GenerateKey with a custom io.Reader and verify that the key generation no longer depends on that reader.
Source
github.com/golang/go/issues/70942

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed