Menu

Random Number Generator

Purpose: Generate one or many random numbers within a chosen range - great for draws, lotteries, sampling and games.

Random Number Generator: How It Works

A random number generator produces values you cannot predict. What 'cannot predict' means in practice depends entirely on which generator is used — and the difference between the two kinds is the difference between a fair game and a broken security system.

Two kinds of random

Pseudorandom (PRNG)Cryptographically secure (CSPRNG)
How it worksDeterministic formula from a seedSeeded from system entropy
Predictable?Yes, given the seed and algorithmNo, by design
SpeedVery fastSlightly slower
SuitsGames, simulations, sampling, shufflingPasswords, tokens, keys, lottery draws
In JavaScriptMath.random()crypto.getRandomValues()

A pseudorandom generator produces a sequence that passes statistical tests for randomness while being entirely determined by its starting seed. That is a feature for simulations — the same seed reproduces the same run, which makes results reproducible — and a serious flaw anywhere an adversary might benefit from predicting the next value.

Real incidents have followed from this. Online poker sites, lottery systems and session-token generators have all been broken by attackers who observed enough output to recover the internal state and predict every subsequent value.

The modulo bias

The common way to force a random number into a range introduces a subtle unfairness. If a generator produces 0 to 99 and you take the value modulo 3, then 0 and 1 each occur 34 times per 100 while 2 occurs 33 — a bias of about 3%.

The bias grows as the range approaches the generator's own range, and it is invisible in small samples. The correct fix is rejection sampling: discard values in the incomplete final block and draw again. Any generator intended for fairness or security should do this.

What random sequences actually look like

People consistently misjudge randomness. In 100 fair coin flips, a run of six or more identical results is more likely than not — yet such a run looks 'non-random' to almost everyone. Conversely, sequences people construct by hand alternate too often and contain too few runs, which makes hand-made 'random' data easy to identify statistically.

This is why lottery draws frequently produce consecutive numbers, and why a shuffle that feels wrong is often the only genuinely random one. Some music services deliberately make their shuffle less random, because true randomness plays the same artist twice in a row often enough that users report it as broken.

With or without repetition

Drawing 6 numbers from 1–49 for a lottery is sampling without replacement — each number appears at most once. Rolling a die six times is with replacement — repeats are expected. Choosing the wrong mode is the most common practical error, and it changes the probabilities considerably.

True randomness

Hardware generators derive entropy from physical processes — thermal noise, radioactive decay, atmospheric noise. Modern processors include instructions that sample on-chip noise directly. Operating systems mix these sources into an entropy pool that seeds the system's cryptographic generator, which is what any secure random function ultimately draws from.

Frequently Asked Questions

Is Math.random() safe for passwords or tokens?
No. It is a pseudorandom generator, fully determined by its internal state, and an observer with enough output can predict subsequent values. Use crypto.getRandomValues() or an equivalent cryptographic source for anything security-related.
What is modulo bias?
Using the modulo operator to fit random values into a range makes some outcomes slightly more likely than others whenever the range does not divide evenly. The correct approach is rejection sampling — discard values in the incomplete final block and draw again.
Why does my random sequence look non-random?
Because genuine randomness produces clusters and runs. In 100 coin flips, a run of six identical results is more likely than not. Sequences that look 'properly random' to people usually alternate far too often to be real.
What is the difference between with and without replacement?
With replacement allows repeats, like rolling a die several times. Without replacement does not, like drawing lottery numbers. Choosing the wrong mode is the most common error and changes the probabilities substantially.
Can a computer produce true randomness?
Not from software alone, which is deterministic. Hardware generators sample physical processes such as thermal noise, and modern processors include instructions for this. Operating systems mix these into an entropy pool that seeds cryptographic generators.
Is this generator suitable for a prize draw?
For an informal draw, yes. For anything with legal or financial consequence, use a certified randomness source with an auditable process — regulated draws generally require documented, verifiable procedures rather than a web tool.

Related Calculators Tools

Browse all Calculators tools →