Random

A short history

The history of randomness: a sourced timeline

Five thousand years of throwing bones, drawing lots and building machines to be unpredictable on purpose. Every entry is sourced; the folklore is labelled.

By Stuck at Home, LLC · · 78 sourced entries in 5 eras

Five thousand years of people throwing bones, drawing lots and, eventually, building machines to be unpredictable on purpose. Every entry links to where we found it; where the famous version of a story is shaky, we say so.

Before 1500

Bones, lots and oracles

Chance as a tool for games, fairness and talking to the gods — long before anyone could calculate it.

  1. 3rd millennium BCE

    A gaming set from the Burnt CitySources disagree

    Excavations at Shahr-e Sukhteh in south-east Iran produced a board, pieces and dice that the excavators dated to the early-to-mid third millennium BCE, announced in 2004. It is often called one of the oldest gaming sets with dice. Accounts disagree on the details — how many pieces, which game — and the press label “world’s oldest backgammon” is a modern guess, so we keep this one at arm’s length.

    Source: World’s oldest backgammon set found in Iran — Stone Pages archaeology news, 2004
  2. c. 2600 BCEto 2400 BCE

    Pyramid dice in the Royal Game of Ur

    Four-sided dice are as old as six-sided ones. The Royal Game of Ur, one of the oldest complete board games ever found, came out of Sumer with little pyramidal dice; the British Museum’s board is usually dated to around 2600–2400 BCE. Britannica also records cubic dice in Egyptian tombs from about 2000 BCE.

    Source: Dice — Britannica
  3. Antiquity

    Knucklebones: dice before dice

    Long before cubes, people threw astragali — the ankle bones of sheep and goats. A knucklebone can land on only four sides, and not evenly: the two broad faces come up far more often than the two narrow ones, so the game was lopsided from the start. The Met holds bone knucklebone gaming pieces from Egypt made around 1550–1458 BCE, and Greek copies in glass, bronze and faience; Britannica calls them the probable forerunners of dice.

    Sources: Three knucklebone gaming pieces — The Met · Dice — Britannica
  4. Ancient China

    The I Ching’s loaded odds

    Consulting the I Ching builds a hexagram line by line, each line a 6, 7, 8 or 9. The traditional yarrow-stalk ritual gives those four results unequal chances — roughly 1, 5, 7 and 3 in 16 — while the quicker three-coin method gives 1, 3, 3 and 1 in 8. Both produce yin and yang equally often, but with stalks a “changing” yin line is a rare event. A randomizer with a built-in personality, two and a half thousand years before the term existed.

    Source: I Ching divination — Wikipedia (probabilities confirmed by our own enumeration of the 49-stalk procedure)
  5. 4th century BCE

    Athens runs its government by lottery

    Classical Athens filled most civilian offices, its Council of 500 and its jury panels by lot; Aristotle’s Constitution of the Athenians says only a few financial posts and the generals were elected by show of hands. Jurors were sorted with allotment machines, kleroteria: name tickets slotted into a stone frame, then black and white bronze cubes dropped down a tube — a white cube seated a whole row of jurors, a black one sent them home. A fragment of one stands in the Agora Museum. Sortition, the glossary calls it; the Athenians just called it fair.

    Pick a name the Athenian way →Sources: Aristotle, Constitution of the Athenians 64 — Perseus Digital Library · Constitution of the Athenians 43 — Perseus
  6. 2nd c. BCEto 4th c. CE

    Twenty-sided dice, two thousand years before the d20

    Icosahedral dice with Greek letters on their faces survive from Ptolemaic and Roman Egypt. The Met holds three — two of serpentinite and one of faience — and Greek-letter polyhedra from the second century BCE onwards. What they were for, games or oracles, the catalogue does not say, so neither do we.

    Roll a d20 →Sources: Twenty-sided die with Greek letters — The Met · Polyhedron inscribed with Greek letters — The Met
  7. January 49 BCE

    “Iacta alea est”: the die is cast

    Crossing the Rubicon, Caesar reached for a gambler’s phrase. Suetonius, writing in Latin a century and a half later, gives it as iacta alea est — the familiar “alea iacta est” is a later rearrangement. Plutarch says Caesar actually spoke it in Greek, as the saying men use before a desperate throw. Either way, the most famous sentence in Roman history is about dice.

    Sources: Suetonius, Divus Iulius 32 — Bill Thayer’s LacusCurtius · Plutarch, Life of Pompey 60 — LacusCurtius
  8. 1st century CE

    Casting lots, sacred and ordinary

    Deciding by lot was as normal in the ancient world as voting is now. In the Acts of the Apostles the eleven choose Judas’s replacement by lot — “and the lot fell upon Matthias.” Romans practised a literary version, opening Virgil’s Aeneid at random for a prophecy; the Historia Augusta says the young Hadrian, anxious about the emperor Trajan’s favour, consulted this “Vergilian oracle” and drew lines about a future king of Rome.

    Sources: Acts 1:26 — King James Bible (Project Gutenberg) · Historia Augusta, Life of Hadrian 2.8 — LacusCurtius
  9. Roman era – c. 1450

    Dice slowly learn to be fair

    Archaeologists Jelmer Eerkens and Alex de Voogt compared dated dice from Roman, medieval and Renaissance sites in the Netherlands. Roman dice were often lopsided and uneven; designs grew more cubic from about 1250, and by about 1450 dice were highly standardised, with opposite faces adding up to seven. Fair dice arrived a century before anyone could calculate what “fair” meant.

    Roll one →Source: No Dice Left Unturned — Archaeology magazine, May/June 2018
  10. 1268–1797

    Venice elects its Doge by lot (and gives us “ballot”)

    For five centuries Venice chose its head of state through a ten-round procedure that alternately shrank an electoral college by drawing lots and enlarged it by voting — a design meant to make the outcome impossible to buy. From 1328 the lots were drawn by a boy, the ballottino, chosen as the first boy a designated councillor met on leaving St Mark’s on election day. His title comes from ballotta, the little voting ball, which is also where English got the word “ballot”.

    Sources: Electing the Doge of Venice: Analysis of a 13th Century Protocol — Mowbray & Gollmann, 2007 (PDF) · ballot — Online Etymology Dictionary
  11. c. 1300 · 1560s

    “Random” starts out meaning fast

    The English word began as a word for speed, not chance. Middle English randon (around 1300) meant impetuosity or speed, from Old French randon, a rush, from randir, “to run fast”. In the 1560s “at random” meant “at great speed”, and so “carelessly, without aim”; the adjective for “having no definite purpose” followed in the 17th century. The mathematical sense came much later still.

    Source: random — Online Etymology Dictionary
  12. 1446 · 1569

    The first public lotteries

    Public lotteries in the modern sense appear in 15th-century Burgundy and Flanders, where towns raised money for walls and for the poor; the Bruges archives record one held by the widow of the painter Jan van Eyck on 24 February 1446. England’s first state lottery was proclaimed by Elizabeth I in 1567 to pay for harbour repairs; after delays, the drawing began at the west door of St Paul’s Cathedral on 11 January 1569 and ran day and night until May.

    Sources: A History of English Lotteries — John Ashton, 1893 (Project Gutenberg) · The First English National Lottery — History Today · Lottery — Britannica
  13. 16th century

    Genoa invents the numbers game

    Italy’s Lotto is still called the lotto di Genova. It grew out of betting on the twice-yearly renewal of five members of the Republic’s governing councils, who were drawn by lot from 120 names — later 90 — kept in an urn called the seminario. Citizens wagered on which names would come out; replace names with numbers and you have a game that spread across the Italian states and still draws from 1 to 90 today.

    Draw five different numbers →Sources: Lotto — Enciclopedia Treccani · Come si gioca al Lotto — Lotto Italia
  14. “Han dynasty”

    Keno paid for the Great WallLegend, not record

    A story repeated on a thousand casino websites says a Han-dynasty lottery — the “white pigeon ticket” — funded the Great Wall of China. No document supports it. The white-pigeon lottery, baige piao, is recorded as a popular game of Qing-dynasty Guangdong, and its tickets used characters from the Thousand Character Classic, a text composed in the 6th century CE — centuries after the Han dynasty ended. A good legend; not history.

    Sources: Keno — Britannica (archived) · Thousand Character Classic — Wikipedia

1500–1900

Luck gets a mathematics

Gamblers’ questions become a science: probability, the law of large numbers, the bell curve.

  1. c. 1563–64printed 1663

    Cardano writes the first book on games of chance

    The physician, astrologer and compulsive gambler Gerolamo Cardano finished his Liber de ludo aleae — the Book on Games of Chance — in the early 1560s. It sat unpublished until 1663, nearly a century after he wrote it and long after his death. MacTutor calls it the first foray into what became probability theory: someone finally counting the ways dice can fall instead of praying over them.

    Source: Girolamo Cardano — MacTutor History of Mathematics
  2. Summer 1654

    Two letters invent probability

    In 1654 Blaise Pascal and Pierre de Fermat exchanged letters about how to split the stakes of an unfinished game — the “problem of points” — and about a bet on throwing double sixes. Pascal wrote on 29 July that the dice question had come from the Chevalier de Méré, a gambler who could pose problems he could not solve. Their correspondence is usually taken as the birth of mathematical probability, and it was prompted by a man who wanted to know whether a bet was any good.

    The double-six bet, worked out →Sources: Fermat and Pascal on Probability, the 1654 letters in translation — University of York · Blaise Pascal — MacTutor
  3. 1657

    Huygens prints the first treatise on chance

    Christiaan Huygens heard about the Pascal–Fermat work on a visit to Paris in 1655 and went home to write it up properly. His short De ratiociniis in ludo aleae — On Reasoning in Games of Chance — was printed in 1657, the first published treatment of the calculus of probabilities and, for half a century, the textbook.

    Source: Christiaan Huygens — MacTutor
  4. 1713

    The law of large numbers, proved

    Jacob Bernoulli worked out his “golden theorem” in the 1680s and 90s but Ars Conjectandi appeared only in 1713, eight years after his death, from an unfinished manuscript. It contains the first proof of what we now call the law of large numbers: run a chance experiment enough times and the observed frequency almost certainly settles near the true probability. It is the reason a thousand coin flips are trustworthy and ten are not.

    Watch it happen with a coin →Sources: Jacob Bernoulli — MacTutor · Jakob Bernoulli — Britannica
  5. 1718bell curve 1733

    The Doctrine of Chances and the first bell curve

    Abraham de Moivre, a Huguenot refugee scraping a living in London coffee-houses, published The Doctrine of Chances in 1718. In a Latin pamphlet dated 13 November 1733 he showed that the ragged histogram of many coin tosses is approximated by a smooth curve — the first appearance of the normal distribution. Every bell curve since descends from a man calculating odds for gamblers.

    Source: Abraham de Moivre — MacTutor
  6. 4 April 1726

    The oldest lottery still running

    The Dutch Generaliteitsloterij was founded on 4 April 1726, selling tickets in the Ridderzaal in The Hague; renamed the Nederlandse Staatsloterij in 1848, it is widely described as the oldest lottery still in operation. Three centuries of draws, and counting.

    Source: Geschiedenis — Nederlandse Loterij
  7. 1733in full 1777

    Buffon’s needle (and the π myth)

    In 1733 the Comte de Buffon presented the Paris Academy with a memoir on franc-carreau, a coin-on-tiles game, which brought calculus into probability and included the question now called Buffon’s needle: drop a stick on a floor of parallel boards — what is the chance it crosses a line? The full version appeared in 1777. The popular story that Buffon used it to estimate π is a myth: historians find no evidence he made the link. It was Laplace, in 1812, who pointed out that repeating the experiment estimates π — an ancestor of today’s Monte Carlo methods.

    Sources: Buffon: Did He Actually Throw Sticks? — EMS Newsletter, 2014 (PDF) · Georges Buffon — MacTutor
  8. 1812essay 1814

    Laplace: chance is just what we don’t know

    Pierre-Simon Laplace’s Théorie analytique des probabilités (1812) organised a century of results into one system. His popular Essai philosophique of 1814 added the famous thought experiment of an intelligence that, knowing every force and position in the universe, would find nothing uncertain — later nicknamed Laplace’s demon. On that view there is no such thing as chance, only ignorance. Quantum physics would have something to say about that a century later.

    Source: Pierre-Simon Laplace — MacTutor
  9. 1877 · 1889

    The Galton board: a bell curve out of chaos

    Francis Galton built a box of pins in a staggered “quincunx” pattern and poured lead shot through it. Every pellet darts left or right at random at each pin, yet the pile that collects in the slots below takes the smooth shape of the bell curve, every time. He showed it in Royal Institution lectures in the 1870s, including one on 9 February 1877, and described it in Natural Inheritance (1889). Modern versions sit on office desks as toys.

    Sources: Natural Inheritance — Francis Galton, 1889 (Internet Archive full text) · The Book of Why, chapter 2 — Pearl & Mackenzie (PDF)
  10. 1882 · 1919

    The one-time pad: the only unbreakable cipher

    Combine every letter of a message with a letter of truly random key as long as the message, never reuse the key, and the cipher cannot be broken — not by cleverness, not by computers, not ever. A Sacramento banker, Frank Miller, described the idea for telegraph codes in 1882; AT&T engineer Gilbert Vernam patented a teleprinter version (filed 1918, granted 22 July 1919), and the Army’s Joseph Mauborgne helped make it a true one-time system. In 1949 Claude Shannon proved it perfectly secret. The catch is the whole subject of this page: you need an endless supply of genuinely random key.

    Sources: US Patent 1,310,719, Secret Signaling System — Google Patents · Communication Theory of Secrecy Systems — Shannon, 1949 (transcription) · Frank Miller: Inventor of the One-Time Pad — Bellovin, history papers
  11. 1888

    Venn draws a random walk with the digits of π

    In the third edition of The Logic of Chance, John Venn — of the diagrams — drew a wandering path in which each digit of π from 0 to 7 chose one of eight compass directions. He used William Shanks’s 707-place calculation and dropped the 8s and 9s, leaving 568 steps. The phrase “random walk” would not be coined until 1905; the picture came first.

    Source: The Logic of Chance, 3rd edition (1888), ch. V — Internet Archive full text
  12. 1 May 1890

    Galton: “nothing superior to dice”

    In a short note in Nature, Francis Galton described wooden dice whose faces carried values of the normal curve, using all 24 positions a cube can land in, so that a statistician could draw random normal numbers by hand. “As an instrument for selecting at random,” he wrote, “I have found nothing superior to dice.” Shaken in a basket, he explained, they hurtle against one another and the ribs of the basket-work so variously that their starting positions give no clue to how they will land.

    Sources: Dice for Statistical Experiments, Nature 42 (1890) — galton.org facsimile (PDF) · Dice for Statistical Experiments — Nature
  13. 1898

    Death by horse kick, and the law of small numbers

    Ladislaus von Bortkiewicz tabulated soldiers killed by horse kicks in fourteen Prussian army corps over twenty years — 280 corps-years, 196 deaths. The yearly counts per corps (no deaths in 144 corps-years, one in 91, two in 32, three in 11, four in 2) match the Poisson distribution almost exactly: rare events, arriving at random, make a very particular shape. Statisticians have been using his horses ever since.

    Sources: Das Gesetz der kleinen Zahlen — Bortkiewicz, 1898 (Internet Archive full text) · Ladislaus Bortkiewicz — MacTutor

1900–1955

Tables and machines

Statisticians need random numbers by the thousand, and start printing and generating them.

  1. 18 August 1913

    Black, 26 times in a rowSources disagree

    The most-repeated story about the gambler’s fallacy: at the Monte Carlo casino, black came up 26 times running at roulette while players bet ever more heavily on red, certain it was “due”. On a fair single-zero wheel the chance of a named colour 26 times in a row is about 1 in 137 million. The arithmetic is solid; the sourcing is thin — the earliest account we could trace is a 1959 popular book, so we file it under famous rather than documented.

    Why the wheel has no memory →Source: How to Take a Chance (Huff & Geis, 1959), as quoted in MIT OpenCourseWare 6.0002 lecture 6 (PDF)
  2. 1925 · 1935

    Fisher makes randomisation the rule of science

    At Rothamsted agricultural station, R. A. Fisher argued that treatments in an experiment should be assigned strictly at random, so that chance itself — not the scientist’s judgement — guarantees the test is fair. The Design of Experiments (1935) opens with a lady who claims she can taste whether milk or tea went into the cup first: give her eight cups, four of each, in random order, and the chance of guessing all four right by luck is exactly 1 in 70.

    Sources: Sir Ronald Aylmer Fisher — MacTutor · The Design of Experiments — R. A. Fisher (Internet Archive full text)
  3. 1927

    The first published table of random numbers

    Statisticians running experiments needed random numbers by the thousand, and copying them from dice was slow. L. H. C. Tippett’s Random Sampling Numbers, in Karl Pearson’s series Tracts for Computers, supplied 41,600 digits lifted from a 1925 census report — the first published table of its kind. Later testers found it passed their checks.

    Source: History of Uniform Random Number Generation — L’Ecuyer, Winter Simulation Conference 2017 (PDF)
  4. 1938 · 1964

    The Fisher–Yates shuffle

    R. A. Fisher and Frank Yates’s Statistical Tables included random digits picked from a table of logarithms and described a pencil-and-paper way to put a list into random order — the procedure every programmer now knows as the Fisher–Yates shuffle. Richard Durstenfeld published the efficient computer version in 1964 as “Algorithm 235: Random permutation”; Knuth made it famous. It is how this site shuffles a list.

    Shuffle a list →Sources: History of Uniform Random Number Generation — L’Ecuyer, 2017 (PDF) · Algorithm 235: Random permutation — Durstenfeld, CACM 1964 (record)
  5. 1938–39

    A spinning disc, a flashing lamp and four tests

    Maurice Kendall and Bernard Babington Smith set out what a random table should satisfy and proposed four tests that became standard — frequency, serial, poker and gap. Then they built one: a cardboard disc of ten numbered sectors spinning at about 250 turns a minute, lit by a lamp flashing at random moments roughly every two seconds, while a human observer wrote down the digit shown. 100,000 digits later, they had the largest random table in existence.

    Sources: History of Uniform Random Number Generation — L’Ecuyer, 2017 (PDF) · A Million Random Digits with 100,000 Normal Deviates — RAND (introduction)
  6. 1946–1949

    The Monte Carlo method gets its name

    Stanislaw Ulam remembered the idea arriving in 1946, while he was convalescing and playing solitaire: instead of calculating the odds of winning, why not lay out a hundred games and count? John von Neumann turned it into a plan for simulating neutrons at Los Alamos in March 1947. Nicholas Metropolis supplied the name — because, he wrote, Ulam “had an uncle who would borrow money from relatives because he ‘just had to go to Monte Carlo.’” The first computer runs were on ENIAC in April 1948; the first paper appeared in 1949. Every weather forecast and risk model that runs thousands of random scenarios descends from it.

    Sources: The Beginning of the Monte Carlo Method — Metropolis, Los Alamos Science 1987 (PDF) · Stan Ulam, John von Neumann, and the Monte Carlo Method — Eckhardt, Los Alamos Science 1987 (PDF) · Los Alamos Bets on ENIAC — Haigh, Priestley & Rope, 2014 (PDF)
  7. 1947 · published 1955

    A million random digits

    In May and June 1947 RAND generated a million digits with an “electronic roulette wheel” — a random pulse source gated about once a second into a 32-place counter — then re-randomised the table to remove small biases it found. A Million Random Digits with 100,000 Normal Deviates appeared in 1955 and became the standard reference for anyone who needed chance on paper.

    The story of the book →Source: A Million Random Digits with 100,000 Normal Deviates — RAND
  8. 1947–48

    The middle-square method

    To feed those first Monte Carlo runs, von Neumann needed random numbers faster than any table could supply, so he invented a recipe: square a number, keep the middle digits, repeat. It is generally described as the first algorithmic random number generator. It supplied the numbers for the 1948 ENIAC runs, and it has a fatal habit — sooner or later it collapses into zero or a short loop.

    Run it on a tape →Sources: History of Uniform Random Number Generation — L’Ecuyer, 2017 (PDF) · Los Alamos Bets on ENIAC — Haigh, Priestley & Rope, 2014 (PDF)
  9. October 1948

    Random numbers in sealed envelopes

    The Medical Research Council’s trial of streptomycin for tuberculosis, designed with the statistician Austin Bradford Hill, decided which patients got the new drug using “a statistical series based on random sampling numbers”, kept in sealed envelopes so no doctor could know or nudge the next allocation. Earlier trials had used chance before, but this one became the landmark that made the randomised controlled trial the standard of medical evidence.

    Sources: Why the 1948 MRC trial of streptomycin used treatment allocation based on random numbers — James Lind Library · Medical Research Council (1948) — James Lind Library record
  10. 1949 · printed 1951

    “In a state of sin”

    At a Monte Carlo symposium in Los Angeles in 1949, the man who had just invented the middle-square method gave its most famous review: “Any one who considers arithmetical methods of producing random digits is, of course, in a state of sin.” He went on: “there is no such thing as a random number — there are only methods to produce random numbers.” In the same talk he showed how to get a perfectly fair result from a biased coin — toss twice, keep heads-tails or tails-heads, discard the rest — a trick still used to clean up hardware random bits.

    Source: Various Techniques Used in Connection With Random Digits — von Neumann, NBS Applied Mathematics Series 12, 1951 (PDF, Los Alamos)
  11. September 1949

    Lehmer’s congruential generator

    At a Harvard symposium on large-scale calculating machines, the number theorist D. H. Lehmer proposed a better recipe: multiply the previous number by a constant and keep the remainder modulo a fixed number. Published in 1951, generators of this family ran almost every computer’s random numbers for the next four decades — the good ones and, as RANDU would show, the bad ones.

    Sources: History of Uniform Random Number Generation — L’Ecuyer, 2017 (PDF) · Random number generators: good ones are hard to find — Park & Miller, 1988 (PDF)
  12. 1951

    A random-number instruction, in Turing’s handbook

    The Ferranti Mark 1, the first commercially available general-purpose computer, had a hardware instruction for randomness. Alan Turing’s own programmers’ handbook explains that the instruction /W “puts random digits into the twenty least significant digits of the accumulator”. The University of Manchester credits Turing with contributing it; a later history reports it fell out of use, partly because a program that used it could never be run the same way twice for debugging.

    Sources: Alan Turing’s Manual for the Ferranti Mk. I — University of Manchester (Computer 50) · Dr. Alan M. Turing at The University of Manchester — Digital 60

1955–1995

The computer learns to roll dice

Recipes for pseudo-randomness, the famous failures, and the first hardware sources.

  1. 1 June 1957

    ERNIE picks the first Premium Bond

    Britain’s Electronic Random Number Indicating Equipment was built at the Post Office Research Station at Dollis Hill by Colossus veterans — Tommy Flowers, Sydney Broadhurst and Harry Fensom among them — to pick Premium Bond winners from the random movement of electrons through neon gas. It took 16 minutes to produce the first winning number and ran for more than 55 hours to finish the first draw. A young mathematician, Stephanie “Steve” Brook — later Dame Stephanie Shirley — worked on the statistics that checked it really was random.

    Source: GPO ERNIE I — Science Museum Group collection
  2. 1960s

    RANDU: the random numbers that fell in planes

    IBM shipped a random number routine called RANDU with its System/360 computers — multiply by 65,539, keep the remainder modulo 231 — and it was used everywhere for two decades. It had a hidden flaw: every three consecutive outputs obey a simple equation, so plotted in three dimensions all the “random” points lie on just 15 flat planes. George Marsaglia’s 1968 paper, “Random Numbers Fall Mainly in the Planes”, showed the same lattice lurks in every generator of this family.

    Sources: Random Numbers Fall Mainly in the Planes — Marsaglia, PNAS 1968 · The Use and Abuse of Random Numbers — lecture slides, CERN Indico (PDF)
  3. 1969

    Knuth’s cautionary tale

    Volume 2 of Donald Knuth’s The Art of Computer Programming opens its chapter on random numbers with a confession: his own deliberately complicated “super-random” recipe, Algorithm K, almost immediately settled on a number that turned back into itself. The moral, as it is usually quoted: random numbers should not be generated with a method chosen at random; some theory must be used. The book is not online, so we have the quotation only second-hand.

    Sources: The Art of Computer Programming — Knuth’s page at Stanford · A New Twist on Random Numbers — USENIX ;login:, 2001 (PDF, quotes the passage)
  4. 1 December 1969

    The draft lottery that wasn’t mixed

    The first US draft lottery since 1942 ranked birthdays by drawing 366 capsules from a glass container. The capsules had gone into the box month by month, January to December, and the stirring did not undo it: January birthdays averaged a draft number of 201, December birthdays 121. Statisticians raised the alarm within weeks, and the 1970 lottery used a revised procedure. Nobody cheated; the drum simply remembered.

    The full story →Sources: Vietnam Lotteries — US Selective Service System (archived) · Nonrandom Risk: The 1970 Draft Lottery — Journal of Statistics Education, 1997
  5. 24 April 1980

    The Triple Six Fix

    Pennsylvania’s Daily Number came up 6-6-6 after announcer Nick Perry and lottery official Edward Plevel injected latex paint into every ball except the 4s and 6s, so only those could float up. Eight possible results instead of a thousand, heavy bets on exactly those combinations, and a $3.5 million payout. Perry was convicted in 1981.

    Rig a drum yourself →Sources: 666 an infamous mark of state lottery fix in 1980 — Pittsburgh Tribune-Review (archive) · Triple Six Fix — WESA, 2015
  6. 19 May 1984

    The game board that repeated itself

    Michael Larson won $110,237 on CBS’s Press Your Luck after studying taped episodes frame by frame and discovering that the “random” prize board cycled through a small number of fixed sequences. His 47-spin run had to be split across two broadcasts. The board was never rigged — it just wasn’t random, and one viewer had the patience to prove it.

    Source: Michael Larson and the Press Your Luck scandal — Biography.com
  7. May 1986

    A generator with a proof

    Lenore Blum, Manuel Blum and Michael Shub published a generator that is provably unpredictable, under a standard hardness assumption: square a number modulo the product of two large primes and output one bit each time. Too slow for everyday use, it mattered as a proof that unpredictability could be a theorem rather than a hope.

    Source: A Simple Unpredictable Pseudo-Random Number Generator — SIAM Journal on Computing, 1986 (record)
  8. October 1988

    “Good ones are hard to find”

    After two decades of broken generators, Stephen Park and Keith Miller published a plea in Communications of the ACM titled “Random number generators: good ones are hard to find”, and proposed a “minimal standard”: multiply by 16,807, take the remainder modulo 231 − 1. Not the best possible generator, they said, but one that was known to work — a floor below which nobody should fall.

    Source: Random number generators: good ones are hard to find — CACM 1988 (PDF)
  9. 1994

    /dev/random

    Theodore Ts’o’s random number generator for the Linux kernel, behind the files /dev/random and /dev/urandom, carries his copyright from 1994. It gathers unpredictable timing from hardware events into a pool and stretches it with a cryptographic generator. Overhauled in 2022: Linux 5.17 replaced its old SHA-1 hashing with BLAKE2s, and 5.18 made the two files behave identically.

    Sources: drivers/char/random.c — Linux kernel source · Random number generator enhancements for Linux 5.17 and 5.18 — Jason Donenfeld
  10. April 1994

    The keno machine with no clock

    Daniel Corriveau beat the Montreal Casino’s new electronic keno three times running — reportedly picking 19 of 20 numbers — and found himself investigated by the fraud squad. The fault was the casino’s: the machine lacked the clock meant to reset its generator, so it replayed the same sequence every time it was powered up. Loto-Québec admitted it had never tested the game and paid his family more than C$620,000.

    Source: RISKS Digest 15.80, April 1994
  11. 1995

    Diehard: a battery of tests on a CD-ROM

    George Marsaglia — the man who exposed RANDU — released the Diehard battery of randomness tests on “The Marsaglia Random Number CDROM”, alongside large files of random numbers, with funding from the US National Science Foundation. For a decade it was the test a new generator had to survive.

    Source: The Marsaglia Random Number CDROM — Florida State University (archived)

1995–today

Noise, physics and proof

Lava lamps, radio static, atoms and quantum light — and the hard lessons about what happens when the randomness is weak.

  1. January 1995

    The regulator who predicted the machines

    Ronald Dale Harris, a Nevada Gaming Control Board engineer whose job was to catch cheating software, wrote a program to predict the outcomes of electronic keno and video poker. When an accomplice hit a $100,000 keno jackpot at an Atlantic City casino, the size of the win itself raised suspicion; nothing was paid, and Harris was arrested on landing back in Las Vegas. He had also secretly rigged slot machines, and in 1998 was sentenced to seven years.

    Sources: Harris chronology — Las Vegas Sun, 1997 · Slot cheater receives seven year prison term — Las Vegas Sun, 1998
  2. 1995

    Diceware: passphrases from real dice

    Arnold Reinhold’s Diceware turns five rolls of an ordinary die into a five-digit number that picks one word from a list of 7,776 (that is 65), giving about 12.9 bits of randomness per word. Six or more words make a passphrase no computer can guess and a human can remember — physical randomness for the one job this site won’t do.

    Source: The Diceware Passphrase Home Page — Arnold G. Reinhold
  3. September 1995

    Two students break Netscape’s randomness

    Ian Goldberg and David Wagner, first-year PhD students at Berkeley, noticed that Netscape Navigator seeded the generator behind its secure connections from just the time of day and two process IDs. With an account on the same machine, trying every candidate seed took about 25 seconds; from outside, minutes. The lesson that has echoed through every breach since: a strong cipher is worthless if the random numbers feeding it are guessable.

    Source: Randomness and the Netscape Browser — Goldberg & Wagner, Dr. Dobb’s Journal, January 1996
  4. 1996

    Lavarand: seeding a generator with lava lamps

    Three Silicon Graphics engineers — Landon Curt Noll, Robert Mende and Sanjeev Sisodiya — patented the idea of pointing a camera at a chaotic scene, hashing the picture and using the hash to seed a generator; their working example was a row of lava lamps. US Patent 5,732,138 was filed on 29 January 1996 and granted in March 1998.

    Photograph our lamp wall →Source: US Patent 5,732,138 — Google Patents
  5. May 1996 – 2023

    HotBits: random numbers from radioactive decay

    John Walker’s HotBits served random bytes over the web by timing the clicks of a Geiger–Müller tube — first from krypton-85, then from a caesium-137 check source. Each decay is genuinely unpredictable, which made it a favourite demonstration of “true” randomness for 26 years. The radioactive generator was retired at midnight UTC on 1 January 2023.

    Sources: HotBits: Genuine Random Numbers — Fourmilab · HotBits hardware — Fourmilab
  6. 1997 · published 1998

    The Mersenne Twister

    Makoto Matsumoto and Takuji Nishimura’s generator, released in 1997 and published in January 1998, has a period of 219937 − 1 and is evenly spread in 623 dimensions. It became the default in Python, R, Ruby and MATLAB. It is not for secrets: it is a linear recurrence whose entire state is 624 words, so a long enough run of outputs predicts the rest.

    Sources: Mersenne Twister — the original paper (PDF) · random — Python 3 documentation
  7. 1998

    RANDOM.ORG goes online

    Mads Haahr started building a generator from atmospheric radio noise in the summer of 1997, while working for a four-person startup on an online gambling engine. The gambling product was dropped; the random numbers were not. He put the service online at Trinity College Dublin in 1998. The first radio was a $10 receiver from Radio Shack.

    Source: The History of RANDOM.ORG
  8. 1999 · 2012

    Randomness on the chip

    Intel’s first hardware random number generator arrived in 1999 inside the 82802 Firmware Hub used with its i8xx chipsets, amplifying the thermal noise of resistors. Its successor, the RDRAND instruction, draws thermal noise from inside the silicon itself and shipped with the Ivy Bridge processors in 2012 — a true random source in most laptops, feeding the operating system that feeds your browser.

    Sources: The Intel Random Number Generator — Jun & Kocher, Cryptography Research, 1999 (PDF) · Behind Intel’s New Random-Number Generator — IEEE Spectrum
  9. October 2000

    NIST writes down the tests

    Special Publication 800-22, “A Statistical Test Suite for Random and Pseudorandom Number Generators for Cryptographic Applications”, gave the field a shared checklist: 15 statistical tests for binary sequences. Revised in 2008 and 2010, with a further revision announced in 2022. NIST’s own warning stands: passing statistical tests is no substitute for cryptanalysis.

    Source: SP 800-22 Rev. 1a — NIST Computer Security Resource Center
  10. September 2005 · 2014

    “Less random, so it seems more random”

    When Apple released iTunes 5 on 7 September 2005 it added Smart Shuffle, after listeners complained that shuffle “wasn’t random”. Steve Jobs was reported saying: “We’ve actually added Smart Shuffle to make it less random. But it seems more random.” Spotify hit the same wall in 2014: its shuffle had always been a textbook Fisher–Yates, but when three songs by one artist came up in a row, users cried foul, so it switched to an algorithm that spreads each artist out. Real randomness clumps; people prefer the fake kind.

    See why clumps are normal →Sources: Apple Introduces iTunes 5 — BetaNews, 7 September 2005 (archived) · How to shuffle songs? — Spotify Engineering, 2014 (archived)
  11. 2006–2015

    Dual_EC_DRBG: the generator with a possible back door

    One of four generators in NIST’s 2006 standard SP 800-90 was built on elliptic curves. At the CRYPTO 2007 rump session, Microsoft’s Dan Shumow and Niels Ferguson showed that whoever chose one of its constants could hold a secret key that predicts all future output after seeing about 32 bytes — while carefully saying they were not claiming anyone had. In September 2013, reporting on the Snowden documents raised exactly that concern; in December, Reuters reported a secret $10 million NSA contract that made it the default in RSA’s BSafe toolkit. NIST pulled it from the draft standard in April 2014.

    Sources: On the Possibility of a Back Door in the NIST SP800-90 Dual Ec Prng — Shumow & Ferguson, CRYPTO 2007 rump session (PDF) · NIST Removes Cryptography Algorithm from Random Number Generator Recommendations — NIST, April 2014 · Secret contract tied NSA and security industry pioneer — Reuters, December 2013 (archived)
  12. August 2007

    TestU01: Crush and BigCrush

    Pierre L’Ecuyer and Richard Simard’s C library became the modern proving ground for generators, with three batteries of rising severity: SmallCrush runs in seconds; Crush applies 96 tests to about 235 numbers; BigCrush applies 106 tests to about 238. Even the Mersenne Twister fails two tests in each of the larger batteries — a reminder that “passes the tests” is always relative to the tests.

    Source: TestU01: A C Library for Empirical Testing of Random Number Generators — ACM TOMS 2007 (PDF, archived)
  13. 2001 · 2007

    “Chosen by fair dice roll.”

    Two cartoons became the field’s running jokes. Dilbert’s 2001 tour of accounting meets the “random number generator”: a troll chanting nine nine nine nine nine nine. (“Are you sure that’s random?” “That’s the problem with randomness: you can never be sure.”) And xkcd #221, from 2007, shows a function that returns 4 — chosen by fair dice roll, guaranteed to be random. Three years later a real company would earn it.

    Sources: xkcd #221, Random Number · Dilbert, 25 October 2001 (archived)
  14. 2006–2008

    The Debian bug: 32,767 possible keys

    In 2006 a Debian maintainer commented out two lines of OpenSSL to silence warnings from a debugging tool. The lines fed entropy into the random pool. For twenty months, every key generated on an affected system was seeded only by the process ID — 32,767 possibilities per architecture — so SSH, VPN and web-server keys could simply be enumerated. Luciano Bello found it in 2008; Debian’s advisory DSA-1571 went out on 13 May. Two lines, two years, millions of weak keys.

    Sources: DSA-1571-1: predictable random number generator — Debian Security Advisory (archived) · CVE-2008-0166 — NIST National Vulnerability Database
  15. 2010 · convicted 2015

    The lottery’s own security chief rigs the computer

    Eddie Tipton, information-security director at the Multi-State Lottery Association, planted code in drawing computers that let him predict winning numbers on three days of the year. A ticket for Iowa’s Hot Lotto jackpot of 29 December 2010 was presented anonymously through lawyers two hours before it expired a year later, and never paid. Convicted in 2015, he admitted in 2017 to rigging draws in Colorado, Wisconsin, Kansas, Oklahoma and Iowa and was sentenced to up to 25 years.

    Four fixed draws, one lesson →Sources: Iowa Lottery Report on Operations, December 2017 (PDF) · Ex-lottery worker convicted of rigging system — CBS News, 2015
  16. 29 December 2010

    Sony’s PlayStation 3 key: the same “random” number every time

    At the Chaos Communication Congress in Berlin, the fail0verflow group showed that Sony had signed PlayStation 3 software using ECDSA without a fresh random number for each signature. The algorithm requires one: two signatures that share the number give away the private key. With Sony’s key, anyone could sign their own code. The slide titled “Sony’s ECDSA code” simply showed xkcd #221.

    Sources: Console Hacking 2010: PS3 Epic Fail — 27C3 schedule · Console Hacking 2010 slides (PDF)
  17. 2012

    Weak keys across the internet

    Nadia Heninger, Zakir Durumeric, Eric Wustrow and J. Alex Halderman scanned the whole internet and computed the private keys of 0.5% of secure web hosts and 0.03% of SSH hosts, because their public keys shared prime factors — almost all of them embedded devices that generated keys at first boot before they had gathered any real randomness. The paper, “Mining Your Ps and Qs”, won Best Paper at USENIX Security.

    Sources: Widespread Weak Keys in Network Devices — factorable.net · Mining Your Ps and Qs — USENIX Security 2012
  18. 2013 · v2 2018

    A public randomness beacon

    NIST switched on a prototype Randomness Beacon in 2013 and upgraded it in 2018: every 60 seconds it publishes 512 fresh random bits, numbered, time-stamped, signed and chained to the previous pulse so that not even NIST can quietly rewrite the past. It is meant for things that must be verifiably random after the fact — a draw, an audit sample — and it comes with a warning in capitals: do not use beacon values as secret keys.

    Sources: Interoperable Randomness Beacons — NIST · NIST Randomness Beacon — live pulses
  19. August 2013

    A broken Android generator empties bitcoin wallets

    On 11 August 2013 Bitcoin.org warned that a flaw in Android’s secure random number generator left every wallet created on the platform open to theft. Google confirmed three days later that the generator was improperly initialised. In some cases the “random” numbers in transaction signatures repeated — the PlayStation mistake again, this time with money attached.

    Sources: Android Security Vulnerability — Bitcoin.org, 11 August 2013 · Some SecureRandom Thoughts — Android Developers Blog, 2013
  20. May 2014

    OpenBSD moves to ChaCha20

    OpenBSD 5.5 switched its arc4random functions from the RC4 cipher to ChaCha20 — the stream cipher that now sits under many systems’ secure generators. The manual page also makes a point this site cares about: use arc4random_uniform(), because arc4random() % n suffers from modulo bias.

    Why modulo bias matters here →Sources: arc4random(3) — OpenBSD manual pages · OpenBSD 5.5 release notes
  21. 2014 · 2018

    PCG and xoshiro: the new fast generators

    Melissa O’Neill’s PCG family (2014) and David Blackman and Sebastiano Vigna’s xoshiro/xoroshiro family (2018) now dominate fast, non-cryptographic generation. NumPy’s modern random API made PCG64 its default in version 1.17 (July 2019), while its legacy functions keep the Mersenne Twister; xoshiro variants are the defaults in Julia, Lua, GNU Fortran and .NET 6.

    Sources: The PCG Paper — pcg-random.org · Scrambled Linear Pseudorandom Number Generators — Blackman & Vigna, arXiv · NumPy 1.17.0 release notes
  22. December 2015

    Chrome fixes Math.random()

    Until late 2015, the V8 engine behind Chrome and Node.js produced Math.random() with MWC1616, a weak generator whose patterns a Betable engineer famously ran into. Within days of the flaw being publicised, V8 switched to xorshift128+ (shipped in Chrome 49); Firefox and Safari followed. The V8 team added the sentence every web developer should know: even the fix is not cryptographically secure — for that, use crypto.getRandomValues().

    What this site uses instead →Sources: There’s Math.random(), and then there’s Math.random() — V8 blog, 2015 · TIFU by using Math.random() — Betable Engineering, 2015 (archived)
  23. 26 January 2017

    The Web Cryptography API becomes a standard

    The W3C published the Web Cryptography API as a Recommendation, standardising crypto.getRandomValues(): a function that fills an array with cryptographically strong random values from the device’s own secure source, up to 65,536 bytes at a time. It is the first line of this site’s number generator.

    How this generator works →Source: Web Cryptography API — W3C Recommendation, 26 January 2017 (archived copy)
  24. November 2017

    A wall of 100 lava lamps

    Cloudflare revived the Lavarand idea at scale: a camera films a wall of about 100 lava lamps in the lobby of its San Francisco office and feeds the video into a secure generator as an extra source of randomness for its servers. Other offices add their own chaos — double pendulums in London, the decay of a small uranium pellet in Singapore, rainbow mobiles in Austin and, since 2025, 50 wave machines in Lisbon.

    Photograph our lamp wall →Sources: Randomness 101: LavaRand in Production — Cloudflare blog, 2017 · Harnessing chaos in Cloudflare offices — Cloudflare blog
  25. April 2018

    Randomness certified by physics

    Peter Bierhorst and colleagues at NIST reported in Nature the first random bits certified by a loophole-free Bell test on entangled photons: 1,024 bits, uniform to within one part in a trillion, that no physical theory forbidding faster-than-light signalling could have predicted. Laplace’s demon, meet quantum mechanics.

    Source: Experimentally Generated Randomness Certified by the Impossibility of Superluminal Signals — arXiv
  26. March 2019

    ERNIE 5 goes quantum

    Sixty-two years after the first draw, ERNIE 5 produced the numbers for the March 2019 Premium Bonds draw in 12 minutes, against about nine hours for ERNIE 4 late in its life, using quantum technology — light — from the Swiss firm ID Quantique. All four earlier ERNIEs had relied on thermal noise. ERNIE 4 retired to the National Museum of Computing at Bletchley Park, down the road from where its ancestor’s makers once broke codes.

    Sources: Premium Bonds take a quantum leap — NS&I, March 2019 (archived) · GAD and ERNIE 5 — UK Government Actuary’s Department
  27. 17 June 2019

    The League of Entropy

    Cloudflare, EPFL, the University of Chile, Kudelski Security and researchers from Protocol Labs launched drand, a distributed randomness beacon in which independent servers jointly sign each round so that no single member can predict or bias it. The 2019 beacon ticked every 60 seconds; today’s mainnet emits a round every 30 seconds and the “quicknet” chain every 3.

    Sources: League of Entropy: Not All Heroes Wear Capes — Cloudflare blog, 2019 · About drand — drand.love
  28. March 2025

    Certified randomness from a quantum computer

    A team from JPMorganChase, Quantinuum, Argonne and Oak Ridge National Laboratories and the University of Texas at Austin used a 56-qubit trapped-ion quantum computer as an untrusted source and classical supercomputers running at a combined 1.1 exaFLOPS to certify 71,313 bits of fresh entropy. Unlike the 2018 Bell-test result, the guarantee rests on assumptions about what is computationally hard — the newest chapter in a very old search for numbers nobody can predict.

    Sources: Harnessing Quantum Computing for Certified Randomness — JPMorganChase · Researchers Achieve Quantum Computing Milestone — UT Austin College of Natural Sciences
Where we looked things up