Part of the complete guide: Provably fair: the complete guide
Pseudo-random numbers: random-looking, not random
A pseudo-random number generator (PRNG) uses a formula. Given a starting value called the seed, it produces a long sequence of numbers that pass statistical tests for randomness. Run it again with the same seed and you get the identical sequence.
That determinism is useful in games and simulations. For a lottery it is dangerous: anyone who learns the seed, or can guess it, can predict every future number. A seed such as the current time in seconds is far easier to guess than people expect.
True random numbers: physical entropy
A true random number generator (TRNG) measures a physical process that cannot be predicted, such as thermal noise in a circuit, timing of keystrokes or radioactive decay. Modern operating systems gather such "entropy" and use it to seed secure generators.
For cryptography, systems combine both: a pool of real entropy that seeds a cryptographically secure PRNG, which then produces as many numbers as needed.
Why a normal RNG is not enough for a lottery
- The operator controls the machine, so you cannot tell whether numbers were drawn or chosen.
- Logs can be edited, so "we checked our logs" is weak evidence.
- A single point of failure or fraud can swing the result.
A famous real-world example: in a US lottery fraud case that came to light in 2015, an insider with access to the random-number software was convicted for rigging draws. Systems where one person controls the generator are risky.
Mechanical draws
Drawing machines with numbered balls feel honest because you can see them. They can still be biased by ball weight or temperature, or tampered with. Regulators handle that through strict procedures, inspection and sealing of equipment, which is slow and expensive but works when enforced.
Public, verifiable randomness
The newer approach is to use randomness produced by someone else, in public, in a way you can verify. A beacon like drand publishes signed random values on a schedule. A lottery then simply says: "the winners are calculated from this value and this ticket list", and anyone can check the calculation.
This replaces "trust our machine" with "check the maths", which is a much stronger position for the player.
What makes a lottery RNG trustworthy
- 1The source of randomness is named and independent of the operator.
- 2The random value did not exist when the ticket list was closed.
- 3The calculation from random value to winners is public and deterministic.
- 4Anyone can repeat the calculation with published data.
- 5The operator has no way to re-run the draw until it likes the result.
A short experiment you can try
Many programming languages let you seed a pseudo-random generator with a number. If you seed it with 42 and print five numbers, then restart and seed with 42 again, you get the same five numbers in the same order. That is exactly why pseudo-random numbers are unsuitable for a lottery on their own: reproducibility is a feature in games and a flaw in a lottery.
Statistical randomness is not security
A generator can pass every statistical test and still be predictable. Statistical randomness means the output looks uniform. Cryptographic security means that, even if you see lots of outputs, you cannot work out the next one. A lottery needs the second property, plus a way to prove nobody interfered.
Why published data beats private logs
- Private logs can be edited after the fact. Public, signed values cannot be changed without detection.
- Private generators have a single operator. A beacon has many.
- A published random value can be re-checked years later.
Example: why a seed matters
A simple generator multiplies the last number by a constant and takes a remainder, starting from a seed. Seed it with 42 and it will produce the same sequence every time, say 17, 91, 4, 66. Anyone who learns the seed and the formula can predict every future number. A secure generator is seeded from unpredictable physical entropy, and uses a stronger formula, so even seeing many outputs reveals nothing about the next one. Lotteries that use software need to protect the seed and the code from insiders, which is why audits and separation of duties exist.
Signs of a trustworthy generator
- Seeded from a hardware or operating system entropy source.
- Cryptographically secure, not a general-purpose maths generator.
- Tested by an independent lab, with a published report.
- Auditable code and controlled access.
Ready?
A weekly draw you can check yourself.
$5 tickets, a public random value, and every result published with the data to recompute it.
Frequently asked questions
Is a PRNG good enough for a lottery?
Only if it is cryptographically secure, seeded with real entropy, and its output can be audited. Even then, players cannot verify it themselves.
What is entropy?
Unpredictable input gathered from physical processes. It is what makes a seed hard to guess.
Are physical draw machines fairer than software?
Neither is automatically fair. Both need oversight, and software can add verifiability.
Can I test a lottery's randomness myself?
You can verify a published draw if the operator gives you the data. Statistical tests on past results can also reveal gross bias.
What is entropy?
Unpredictable input collected from physical processes, used to seed generators.
Is Math.random secure?
No. It is not designed for security. Use a cryptographic generator.
Do lotteries publish their RNG tests?
Some publish certificates or summaries. Look for them.