diff --git a/csharp/change-notes/2021-08-05-insecure-randomness.md b/csharp/change-notes/2021-08-05-insecure-randomness.md index 29b5e5d4884..2a873e963e1 100644 --- a/csharp/change-notes/2021-08-05-insecure-randomness.md +++ b/csharp/change-notes/2021-08-05-insecure-randomness.md @@ -1,2 +1,2 @@ lgtm,codescanning -* Adding `Membership.GeneratePassword()` as a bad source of random data. \ No newline at end of file +* Membership.GeneratePassword()` has been added as a bad source of random data. \ No newline at end of file diff --git a/csharp/ql/src/Security Features/InsecureRandomness.cs b/csharp/ql/src/Security Features/InsecureRandomness.cs index 750c0cc008f..eb4649d54f1 100644 --- a/csharp/ql/src/Security Features/InsecureRandomness.cs +++ b/csharp/ql/src/Security Features/InsecureRandomness.cs @@ -15,7 +15,7 @@ string GeneratePassword() password = "mypassword" + BitConverter.ToInt32(randomBytes); } - // BAD: Membership.GeneratePassword is generates a password with a bias + // BAD: Membership.GeneratePassword generates a password with a bias password = Membership.GeneratePassword(12, 3); return password;