Software
Computers cannot invent randomness, so they harvest it
Deterministic machines produce predictable sequences by definition, and security depends on collecting genuine unpredictability from the physical world.

Most explanations of random number generation stop at the point where it starts to matter. This one carries on.
The short version
- Algorithmic generators are deterministic and repeat given the same seed.
- Cryptographic use requires unpredictable seed material from physical sources.
- Predictable randomness has caused real and severe security failures.
Deterministic machines produce deterministic sequences
A program given the same inputs produces the same outputs, which is the property that makes computers useful and makes randomness impossible. Pseudorandom generators produce sequences that pass statistical tests for randomness while being entirely determined by a starting value.
Given the seed, the whole sequence can be reproduced, which is useful for simulations and fatal for cryptography. This is why the same simulation can be replayed exactly and why the same approach must never generate a key.
Entropy comes from the physical world
Operating systems collect unpredictability from timing of interrupts, sensor noise, disk access variation and dedicated hardware sources. Many processors include a hardware generator based on thermal noise in the silicon, which is genuinely physical. Because a single source might be flawed or backdoored, systems mix several together so that no one source can control the output.
In practice, the mixing is done with cryptographic functions specifically so that partial knowledge of the inputs does not reveal the output.
Failures have been consequential
Devices generating keys at first boot before enough entropy is collected have produced duplicate keys across many units. Researchers scanning the internet have repeatedly found large numbers of devices sharing keys for exactly this reason. Signature schemes that reuse a value which must be unique leak the private key outright, and this has been exploited in the wild.
In the datasheet, these are not theoretical concerns; they are recurring findings in security research.
Blocking versus non-blocking is largely settled
Older systems offered a source that blocked until it judged enough entropy had been gathered, which caused hangs on headless machines at boot. The modern consensus is that once a generator has been properly seeded once, it can produce output indefinitely without blocking. The remaining hard case is the very first boot of a device with no stored seed and no user activity.
Manufacturers address it with hardware sources and by injecting seed material during production.
Statistical randomness is not unpredictability
A sequence can pass every statistical test and still be trivially predictable if the algorithm and state are known. Cryptographic generators add the requirement that observing output must not allow predicting past or future output. That is why general-purpose random functions in programming languages carry explicit warnings against security use.
Mechanically, choosing the wrong function is one of the most common and most severe mistakes in application code.
Implementations differ, and vendors are not obliged to document the differences.
Where it shows up for ordinary users
Every encryption key, session token, password reset link and authentication challenge depends on unpredictable values. Password generators, shuffle functions in games and lottery systems all rest on the same foundations with different consequences for failure.
Physical dice, coin flips and card shuffles remain genuinely random and are still used to generate high-value keys deliberately. The general lesson is that unpredictability is a resource that must be gathered, not a property software can simply assert.
The takeaway
Unpredictability is collected from the physical world. Software can only stretch it, never create it.
Understanding the failure mode tells you more than the feature list does.
Questions readers ask
Is the random function in my programming language safe for passwords?
Almost certainly not. General-purpose generators are fast and predictable by design. Use the library explicitly labelled as cryptographically secure.
Can hardware random generators be trusted?
They are difficult to audit, which is why well-designed systems mix them with other sources rather than relying on them alone.
Also by Junko Ishida
- USB-C solved the connector and not the confusionPower & Batteries
- File formats decide whether your files outlive the softwareSoftware
- Where the electricity goes when everything is switched offPower & Batteries
- The memory effect was real, and it has nothing to do with your phonePower & Batteries





