Random Number Generator: How It Works
A random number generator produces values you cannot predict. What 'cannot predict' means in practice depends entirely on which generator is used — and the difference between the two kinds is the difference between a fair game and a broken security system.
Two kinds of random
| Pseudorandom (PRNG) | Cryptographically secure (CSPRNG) | |
|---|---|---|
| How it works | Deterministic formula from a seed | Seeded from system entropy |
| Predictable? | Yes, given the seed and algorithm | No, by design |
| Speed | Very fast | Slightly slower |
| Suits | Games, simulations, sampling, shuffling | Passwords, tokens, keys, lottery draws |
| In JavaScript | Math.random() | crypto.getRandomValues() |
A pseudorandom generator produces a sequence that passes statistical tests for randomness while being entirely determined by its starting seed. That is a feature for simulations — the same seed reproduces the same run, which makes results reproducible — and a serious flaw anywhere an adversary might benefit from predicting the next value.
Real incidents have followed from this. Online poker sites, lottery systems and session-token generators have all been broken by attackers who observed enough output to recover the internal state and predict every subsequent value.
The modulo bias
The common way to force a random number into a range introduces a subtle unfairness. If a generator produces 0 to 99 and you take the value modulo 3, then 0 and 1 each occur 34 times per 100 while 2 occurs 33 — a bias of about 3%.
The bias grows as the range approaches the generator's own range, and it is invisible in small samples. The correct fix is rejection sampling: discard values in the incomplete final block and draw again. Any generator intended for fairness or security should do this.
What random sequences actually look like
People consistently misjudge randomness. In 100 fair coin flips, a run of six or more identical results is more likely than not — yet such a run looks 'non-random' to almost everyone. Conversely, sequences people construct by hand alternate too often and contain too few runs, which makes hand-made 'random' data easy to identify statistically.
This is why lottery draws frequently produce consecutive numbers, and why a shuffle that feels wrong is often the only genuinely random one. Some music services deliberately make their shuffle less random, because true randomness plays the same artist twice in a row often enough that users report it as broken.
With or without repetition
Drawing 6 numbers from 1–49 for a lottery is sampling without replacement — each number appears at most once. Rolling a die six times is with replacement — repeats are expected. Choosing the wrong mode is the most common practical error, and it changes the probabilities considerably.
True randomness
Hardware generators derive entropy from physical processes — thermal noise, radioactive decay, atmospheric noise. Modern processors include instructions that sample on-chip noise directly. Operating systems mix these sources into an entropy pool that seeds the system's cryptographic generator, which is what any secure random function ultimately draws from.