About Random Number Generation

// What is randomness?

A random number is one that cannot be predicted in advance. True randomness comes from physical phenomena — radioactive decay, thermal noise, atmospheric interference — processes that are fundamentally unpredictable even in principle.

Computers are deterministic machines: given the same input, they always produce the same output. This makes true randomness difficult to generate in software. Most programming languages use a pseudo-random number generator (PRNG) — an algorithm that produces sequences that look random but are mathematically predictable if you know the seed.

RNG.DK uses crypto.getRandomValues() — the browser's cryptographically secure random number interface. In practice, browsers implement this as a secure PRNG seeded from system entropy sources such as hardware timing, OS noise, and other environmental inputs. The specific implementation varies by browser and platform, but the result is cryptographically strong randomness suitable for fairness-sensitive and security-sensitive use cases.

// The Birthday Paradox

How many people need to be in a room before there's a 50% chance that two of them share a birthday? Most people guess somewhere around 183 — half of 365. The real answer is just 23 people. With 30 people, the probability climbs to 70%. With 50, it's over 97%.

This feels wrong because we intuitively think about the chance that someone shares our birthday. But the question is about any two people — and with 23 people there are 253 possible pairs to check.

People in the room
50.7%
probability of a shared birthday · 23 people · 253 pairs

The Birthday Paradox has real consequences in cryptography and computing. In hash collision attacks, an attacker doesn't need to find something that matches a specific value — just any two inputs that produce the same hash. This is why secure hash functions need to be much larger than you'd naively expect. It's also why good random number generation matters: predictable randomness dramatically increases collision risk.

// Monte Carlo Simulation

Monte Carlo methods use random sampling to solve problems that would be difficult or impossible to solve analytically. The name comes from the Monte Carlo Casino in Monaco — a nod to chance and probability.

A classic example: estimating π using random points. Imagine throwing darts randomly at a square. A quarter-circle is inscribed inside the square. The ratio of darts landing inside the circle to total darts thrown converges to π/4. The more darts, the more accurate the estimate.

—
Estimated π
0
Points thrown
0
Inside circle

Monte Carlo methods are used across science, finance, and engineering: simulating particle physics, pricing complex financial derivatives, modelling climate systems, optimising logistics routes, and rendering realistic lighting in 3D graphics. The quality of the randomness affects the accuracy of the result. For fairness-sensitive or unpredictability-critical uses, a cryptographically strong generator is the right choice. In many scientific simulations, high-quality PRNGs are equally valid — and often preferred for their speed and reproducibility.

// Where is RNG used?

Random number generation is fundamental across a surprisingly wide range of fields:

Cryptography
Generating encryption keys, salts, nonces, and session tokens. Predictable randomness here is catastrophic.
Gaming & Gambling
Slot machines, card shuffling, loot drops. Regulatory bodies require certified RNG quality.
Scientific Simulation
Monte Carlo methods, molecular dynamics, climate modelling, quantum physics simulations.
Statistics & Sampling
Random sampling for surveys, A/B testing, bootstrapping, and statistical inference.
Machine Learning
Weight initialisation, dropout regularisation, data shuffling, and stochastic gradient descent.
Computer Graphics
Path tracing, procedural generation of terrain, textures, and realistic noise patterns.

// PRNG vs CSPRNG

A Pseudo-Random Number Generator (PRNG) like Math.random() is fast and sufficient for games, simulations, and non-security purposes. But it is seeded — meaning its entire future output can be reconstructed if an attacker discovers the seed or observes enough output values.

A Cryptographically Secure PRNG (CSPRNG) like crypto.getRandomValues() adds two critical properties: forward secrecy (knowing past output reveals nothing about future output) and backtracking resistance (knowing the current state reveals nothing about past output). This is achieved by continuously mixing in fresh entropy from hardware sources.

RNG.DK uses crypto.getRandomValues() as its randomness source, making it suitable for fairness-sensitive applications such as lotteries, draws, and games. It is not a substitute for an audited, server-side randomness platform with logging, attestation, or reproducibility guarantees — those are different requirements for different contexts.

For most everyday uses — picking a lottery number, rolling a die, generating a random integer — the difference is academic. But knowing your numbers come from a CSPRNG means you can be confident that no pattern, bias, or predictability is hiding in the results.

// Limitations & scope

RNG.DK is a browser-based tool. Being transparent about what it is — and what it is not — is part of using it responsibly.

No audit or certification. This tool has not been tested or certified by any regulatory body. It is not suitable for use in regulated gambling systems, where certified server-side RNG components with independent audit trails are required.

Browser and OS dependence. The specific implementation of crypto.getRandomValues() varies between browsers and operating systems. All modern implementations are cryptographically strong, but behaviour is not guaranteed to be identical across environments.

No reproducibility. Outputs cannot be reproduced from a seed. If you need repeatable sequences — for testing, simulation replay, or audit purposes — a seeded PRNG is the appropriate tool, not this one.

Client-side only. All generation happens in your browser. Nothing is logged, stored, or transmitted. This also means there is no server-side attestation or tamper-evidence for the outputs.