This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 48 · Nov 24 – 30, 2025

crypto: ignore rand io.Reader where behavior is not specified

Worth knowingstdlib

What changed
The proposal is to start ignoring the random io.Reader parameter of most crypto APIs and always use the system random source (crypto/internal/sysrand.Read). A new GODEBUG=cryptocustomrand=1 would restore the old behavior. For testing with a deterministic random source, a testing/cryptotest package will be added.
Production impact
The source does not say.
Try it
Run a program that calls rsa.GenerateKey with a custom io.Reader and observe that it now uses the system random source unless GODEBUG=cryptocustomrand=1 is set.
Source
github.com/golang/go/issues/70942

Understand it, then run it

Run it now

Todaygo
// This program demonstrates the new behaviour of rsa.GenerateKey
// in Go 1.27.1. The function no longer uses the io.Reader argument
// that was historically ignored. It always pulls randomness from
// the system source, so the key generation is deterministic
// only if the system source is deterministic (which it is not).
package main

import (
	"crypto/rand"
	"crypto/rsa"
	"fmt"
)

func main() {
	// Generate a 2048‑bit RSA key. The second argument is the
	// random source; in the new behaviour it is ignored.
	// Passing rand.Reader is harmless but unnecessary.
	key, err := rsa.GenerateKey(rand.Reader, 2048)
	if err != nil {
		panic(err)
	}
	fmt.Printf("Generated key with public exponent %d\n", key.PublicKey.E)
}

What it printed when we ran it on Go 1.27.1

Generated key with public exponent 65537

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed