Tech Behind ThingsHow the ordinary machinery actually works

Software

Computers cannot invent randomness, so they harvest it

Deterministic machines produce predictable sequences by definition, and security depends on collecting genuine unpredictability from the physical world.

Vivid, blurred close-up of colorful code on a screen, representing web development and programming.
Photograph by Markus Spiske via Pexels
Editorial note. Independent reporting and analysis. Nothing here is sponsored or paid for. How we work.

Most explanations of random number generation stop at the point where it starts to matter. This one carries on.

The short version

  • Algorithmic generators are deterministic and repeat given the same seed.
  • Cryptographic use requires unpredictable seed material from physical sources.
  • Predictable randomness has caused real and severe security failures.

Deterministic machines produce deterministic sequences

A program given the same inputs produces the same outputs, which is the property that makes computers useful and makes randomness impossible. Pseudorandom generators produce sequences that pass statistical tests for randomness while being entirely determined by a starting value.

Given the seed, the whole sequence can be reproduced, which is useful for simulations and fatal for cryptography. This is why the same simulation can be replayed exactly and why the same approach must never generate a key.

Entropy comes from the physical world

Operating systems collect unpredictability from timing of interrupts, sensor noise, disk access variation and dedicated hardware sources. Many processors include a hardware generator based on thermal noise in the silicon, which is genuinely physical. Because a single source might be flawed or backdoored, systems mix several together so that no one source can control the output.

In practice, the mixing is done with cryptographic functions specifically so that partial knowledge of the inputs does not reveal the output.

Failures have been consequential

Devices generating keys at first boot before enough entropy is collected have produced duplicate keys across many units. Researchers scanning the internet have repeatedly found large numbers of devices sharing keys for exactly this reason. Signature schemes that reuse a value which must be unique leak the private key outright, and this has been exploited in the wild.

In the datasheet, these are not theoretical concerns; they are recurring findings in security research.

Blocking versus non-blocking is largely settled

Older systems offered a source that blocked until it judged enough entropy had been gathered, which caused hangs on headless machines at boot. The modern consensus is that once a generator has been properly seeded once, it can produce output indefinitely without blocking. The remaining hard case is the very first boot of a device with no stored seed and no user activity.

Manufacturers address it with hardware sources and by injecting seed material during production.

Statistical randomness is not unpredictability

A sequence can pass every statistical test and still be trivially predictable if the algorithm and state are known. Cryptographic generators add the requirement that observing output must not allow predicting past or future output. That is why general-purpose random functions in programming languages carry explicit warnings against security use.

Mechanically, choosing the wrong function is one of the most common and most severe mistakes in application code.

Implementations differ, and vendors are not obliged to document the differences.

Where it shows up for ordinary users

Every encryption key, session token, password reset link and authentication challenge depends on unpredictable values. Password generators, shuffle functions in games and lottery systems all rest on the same foundations with different consequences for failure.

Physical dice, coin flips and card shuffles remain genuinely random and are still used to generate high-value keys deliberately. The general lesson is that unpredictability is a resource that must be gathered, not a property software can simply assert.

The takeaway

Unpredictability is collected from the physical world. Software can only stretch it, never create it.

Understanding the failure mode tells you more than the feature list does.

Questions readers ask

Is the random function in my programming language safe for passwords?

Almost certainly not. General-purpose generators are fast and predictable by design. Use the library explicitly labelled as cryptographically secure.

Can hardware random generators be trusted?

They are difficult to audit, which is why well-designed systems mix them with other sources rather than relying on them alone.

Softwarerandomnesscryptographyentropysecurity
Junko Ishida
Contributing writer, Tech Behind Things

Junko covers batteries, charging and energy density, and is unimpressed by most battery claims.

Also by Junko Ishida