🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)
🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)

🔧 Programmierung 🕛 kürzlich 4 Min Lesezeit
0

Math.random() Is Not Random Enough. I Found It Building API Keys in a 44K-Star Repo.

↗ Quelle (dev.to)
🗣️ Stimme:
📑 Inhaltsübersicht

I found this in our benchmark corpus, extracted verbatim from . Once the state is known, every future Math.random() call is predictable — including every future token it generates.




CODE
// What you write:
const apiKey = `cal_live_${Math.random().toString(36).substring(2)}`;
// ↑ non-cryptographic, state-recoverable

// After observing ~20 outputs, an attacker runs state recovery:
// → internal 128-bit state reconstructed
// → every future Math.random() call predicted
// → every future API key predicted






CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator.









Why it survives code review



The pattern looks reasonable at a glance:





  • Math.random() literally has "random" in the name

  • The output looks like a long, unpredictable string: k7f2m9p8x3z

  • It works — tokens generate correctly, no runtime errors, tests pass

  • Reviewers focus on business logic, not PRNG security properties



Nobody reviews token generation and asks "is this the cryptographically correct kind of random?" That is a security-specific question that most engineers do not carry into review. The ESLint rule asks it for you.









Where it appears



The Cal.com example was extracted from their Make integration setup at the time of our benchmark snapshot — it may have been updated since. The pattern itself is common:




CODE
// Top Stack Overflow pattern for "generate unique token":
const token = Math.random().toString(36).substring(2, 15);

// Quick session ID:
const sessionId = Date.now().toString(36) + Math.random().toString(36).substring(2);
// Note: concatenating Date.now() adds a predictable timestamp — it adds length
// but no additional unpredictability. The Math.random() entropy is unchanged.

// Invite code:
const inviteCode = Math.random().toString(36).substring(2, 8).toUpperCase();

// The Cal.com pattern:
const apiKey = `cal_live_${Math.random().toString(36).substring(2)}`;






All four are caught by the same ESLint rule. All four are vulnerable to state recovery.









The ESLint rule that catches it



eslint-plugin-node-security/no-math-random-crypto fires whenever Math.random() is assigned to a variable whose name suggests a security-sensitive context: token, key, secret, session, csrf, nonce, auth, otp, and .






Have you scanned your codebase for this pattern yet? Post what you find — I am specifically curious whether it shows up in places you expected or somewhere surprising.






Part of the





📦





| |

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf dev.to.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Hackers Just Poisoned the Rust Supply Chain | Threat Wire
1 Quelle
Hackers Found a Way Into Humanoid Robots | Threat Wire
1 Quelle
Bits und so #1021 (Passwort für Laufwerk)
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Math.random() Is Not Random Enough. I Found It Building API Keys in a 44K-Star Repo.

Thematisch verwandte Begriffe: Mathrandom, Random, Enough, Found · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...