From ddb759d67a33496b482694c4e2de51e9777417d5 Mon Sep 17 00:00:00 2001 From: Tompkins Date: Thu, 4 Apr 2019 08:11:56 -0400 Subject: [PATCH] (docs) remove SecureRandom --- .../java/org/apache/commons/lang3/RandomStringUtils.java | 8 +++----- src/main/java/org/apache/commons/lang3/RandomUtils.java | 5 ++--- 2 files changed, 5 insertions(+), 8 deletions(-) diff --git a/src/main/java/org/apache/commons/lang3/RandomStringUtils.java b/src/main/java/org/apache/commons/lang3/RandomStringUtils.java index 022831203..3380876d7 100644 --- a/src/main/java/org/apache/commons/lang3/RandomStringUtils.java +++ b/src/main/java/org/apache/commons/lang3/RandomStringUtils.java @@ -34,11 +34,9 @@ import java.util.Random; * * RandomStringGenerator instead.

* - *

Note. This class relies on an instance {@link Random}, and instances - * of {@link Random} are not cryptographically - * secure. Consider instead using {@link SecureRandom}, for which we have no utility class, - * to get a cryptographically secure pseudo-random number generator for use by - * security-sensitive applications.

+ *

Note. This class relies on an instance of {@link Random}, and instances + * of {@link Random} are not cryptographically secure. Consider instead using a more + * cryptographically secure pseudo-random number generator, for which we have no utility class. * *

#ThreadSafe#

* @since 1.0 diff --git a/src/main/java/org/apache/commons/lang3/RandomUtils.java b/src/main/java/org/apache/commons/lang3/RandomUtils.java index 6a899dcda..6a4100943 100644 --- a/src/main/java/org/apache/commons/lang3/RandomUtils.java +++ b/src/main/java/org/apache/commons/lang3/RandomUtils.java @@ -23,9 +23,8 @@ import java.util.Random; *

Utility library that supplements the standard {@link Random} class.

* *

Note. Instances of {@link Random} are not cryptographically - * secure. Consider instead using {@link SecureRandom}, for which we have no utility class, - * to get a cryptographically secure pseudo-random number generator for use by - * security-sensitive applications.

+ * secure. Consider instead using a more cryptographically secure pseudo-random + * number generator, for which we have no utility class.

* * @since 3.3 */