Reads the operating system's own random source – /dev/urandom on
Unix and macOS, RtlGenRandom on Windows – rather than R's
Mersenne Twister.
Details
This distinction matters for anything that becomes a key.
set.seed() makes R's generator reproducible BY
DESIGN, and its state can be recovered from its output; a key drawn from
it is guessable. Reading the OS source also leaves R's own random stream
untouched, so generating a key does not perturb a reproducible analysis.
If no OS source can be read the function FAILS rather than falling back to a weaker generator, because a silent downgrade in a key is worse than an error.
See also
derive_key() to stretch a passphrase instead,
pqc_keygen() which uses this for its seeds.
Examples
random_bytes(8)
#> [1] f7 37 d7 3d 3e ed 48 d9
# Independent between calls, unlike a seeded generator.
identical(random_bytes(16), random_bytes(16))
#> [1] FALSE
# R's own stream is not consumed, so a seeded analysis is unaffected.
set.seed(1)
a <- stats::runif(1)
set.seed(1)
invisible(random_bytes(32))
identical(stats::runif(1), a)
#> [1] TRUE
# As hex, for a seed argument.
paste(format(random_bytes(4)), collapse = "")
#> [1] "5675415f"