decider.click

Guide

Are Online Random Generators Actually Random?

Every coin flipper, dice roller and number picker on the web runs on pseudo-randomness. Here is what that means, when it matters, and how to tell the difference.

RT Ronnie Thomas ·28 August 2026·8 min read

It is a reasonable thing to be suspicious about. You press a button on a website and a number appears, and you have no way of seeing where it came from. The honest answer is that almost every generator you will use, including the ones on this site, is pseudo-random. For most purposes that is completely fine. For a few it is not fine at all.

Pseudo-random means deterministic but unpredictable

A pseudo-random number generator is an algorithm. It holds an internal state, and each time you ask for a number it performs an arithmetic operation on that state, returns a value derived from it, and updates the state. Given the same starting state, it will produce exactly the same sequence every time.

That sounds like a fatal flaw and mostly is not. The sequence is designed so that the output is uniformly distributed, has no detectable pattern, and does not repeat for an enormous number of draws. Modern browsers use an algorithm called xorshift128+, whose period runs to roughly 2128 values. You could draw a million numbers a second for the rest of the universe's expected lifetime without seeing the sequence come round again.

So the output passes every statistical test for randomness that matters in daily use. Heads comes up half the time. Every face of a die is equally likely. There is no drift, no memory of the previous result, and nothing you could observe in the output that would let you predict the next value.

Where the deterministic part becomes a problem

Two places, and they are both narrow.

The first is security. Because the sequence is a function of its state, anyone who can work out the state can predict every future value. Researchers have demonstrated recovering the state of a browser's generator from a modest number of observed outputs. That is catastrophic if you are generating a password or a session token, and irrelevant if you are choosing who washes up. For cryptographic purposes browsers provide a separate interface, crypto.getRandomValues, which draws on the operating system's entropy pool.

The second is anything with money or legal obligation attached. A licensed gambling operator cannot use a browser's generator, and neither can a public prize draw of any size. Not because the numbers would be biased, but because there is no audit trail: no way to prove after the fact that the result was not chosen. Certified random number services exist precisely to provide that evidence, and they charge for it.

True randomness, and why it is rarer than you think

The alternative is hardware randomness, drawn from a physical process believed to be genuinely unpredictable rather than merely complicated. Random.org famously samples atmospheric radio noise. Other services use radioactive decay, thermal noise in a resistor, or the timing jitter of an oscillator. Modern processors include an instruction that generates entropy from on-chip thermal noise.

Your own operating system already does something similar. It maintains an entropy pool fed by the microsecond timings of keystrokes, mouse movements, disk operations and network packets, all of them effectively unpredictable, and uses it to seed cryptographic generators. This is what sits behind the secure interface mentioned above.

Here is the part that surprises people: for choosing a restaurant, hardware randomness is no better than the algorithm. Both produce a uniform, unpredictable result. The physical source matters when you need to prove unpredictability to a sceptical third party, not when you need to break a tie.

How to judge a generator you did not write

You usually cannot inspect the code, so judge the claims instead.

  • Be sceptical of "truly random" as a marketing phrase. A site that genuinely uses a hardware source will say what the source is. One that says "100% truly random" with no further detail is describing Math.random() in a bolder font.
  • Check whether the result arrives before the animation. A spinning wheel that takes four seconds has almost always decided the outcome at the moment you clicked. That is not dishonest, but a site that implies the physics of the spin determines the result is misleading you.
  • Ask whether it could be weighted, and whether anyone would benefit. A free tool with no stake in your answer has no reason to bias it. A tool that gives you a result and then sells you something related to that result does.
  • For anything consequential, use a service that certifies and logs. If you would be embarrassed to explain the method to a loser of the draw, the method is not good enough.

What this site does

Every tool here calls your browser's built-in generator directly, maps the result to the available outcomes with no weighting, and displays it. Nothing is transmitted, nothing is logged, and no result is stored beyond your own screen. The coin flip is an even split; the yes or no wheel is twelve equal segments, six each; the dice roller gives every face equal weight; the number generator is uniform across the range you set.

The one deliberate exception is the magic 8-ball, which follows the toy's traditional distribution: ten affirmative answers, five negative and five non-committal. It is an optimist by design, and that is stated on the page rather than hidden.

Which is the general principle worth holding on to. A generator does not have to be perfect. It has to be honest about what it is.

Read next

Random number generator

Uniform draws across any range you set.

Coin flip

Watch a thousand flips converge on half.

The magic 8-ball

Why its odds are deliberately unfair.

All guides