True Random vs Pseudorandom Numbers
Where randomness comes from, why the difference matters for security but rarely for games, and what this tool uses.
True random numbers come from unpredictable physical processes; pseudorandom numbers come from deterministic algorithms. For raffles, games, and sampling the difference is invisible, but for passwords and encryption only true randomness (or cryptographic pseudorandomness seeded from it) is safe. This tool uses the browser's cryptographic source.
Where randomness comes from
True random number generators harvest unpredictability from the physical world: thermal noise, atmospheric noise, the precise timing of your keystrokes. Pseudorandom generators use a deterministic algorithm starting from a seed value; the output looks random but is fully determined by the seed.
Your operating system maintains an entropy pool fed by hardware events and serves it to applications. When this tool calls crypto.getRandomValues, it is drawing from that pool, which puts it on the true-random side of the line for practical purposes.
Math.random and its limits
JavaScript's Math.random is a pseudorandom generator optimized for speed, not unpredictability. Its algorithm is deterministic, and in some engines the internal state can be reconstructed from observed outputs, which lets an attacker predict future values.
For shuffling a playlist or placing game enemies, that is fine. For drawing a contest winner, it is usually fine too, but why settle: the cryptographic source costs nothing extra and removes the entire class of worry.
When the difference actually matters
The difference matters whenever someone has a motive to predict or influence the outcome: passwords, session tokens, encryption keys, lottery systems, and online gambling. Regulated gambling goes further, requiring certified hardware generators and audits, because the incentives to cheat are enormous.
It does not matter for classroom demos, tabletop games, raffle drawings among friends, or statistical sampling. In those settings, any unbiased source, even a coin, is plenty. The failure mode to watch is bias, not predictability.
Verifying fairness yourself
You can sanity-check any generator with a frequency test: generate 10,000 numbers in a small range with duplicates on and count occurrences. Each value should appear roughly equally often; with 10 values, expect each near 1,000, give or take about a hundred from natural variation.
Also check for obvious patterns: no repeating cycles, no stuck values, no correlation between consecutive draws. A quick eyeball of a few hundred outputs catches broken generators fast.
Skip the arithmetic
Draw from the cryptographic source with the free random number generator.
Randomness questions
What is a true random number generator?
A true random number generator derives unpredictability from physical processes like thermal noise or the timing of hardware events, rather than from a deterministic algorithm. In practice, the entropy pool your operating system maintains counts as a true-random source for applications.
Is Math.random truly random?
No. Math.random is a deterministic pseudorandom generator: given its internal state, all future outputs are determined, and in some engines the state can be reconstructed from observed outputs. It is fine for games and demos but the wrong choice for anything security-related.
How does random.org generate numbers?
Random.org samples atmospheric noise with radio receivers and converts it into random numbers. It is the classic public true-random service, though free use is rate-limited, which makes a local cryptographic source more convenient for everyday draws.