Under the hood
Lava lamps, radio static and atoms: where true randomness comes from
Arithmetic can only fake it. For the genuine article, people have pointed cameras at lava lamps, tuned radios to static and counted atoms falling apart. Try the lamp wall yourself.
Skip to the experimentImagine walking into an office lobby and finding a wall of lava lamps — dozens of them, glowing orange and pink, blobs rising and sinking at their own pace. It looks like decoration. It is actually a factory.
A camera watches the wall. Every so often it takes a picture, and the picture is turned into a long string of digits that nobody could have predicted, because nobody can predict exactly where every blob and every flicker of light will be. Those digits help lock the connections of a good slice of the internet.
That is the difference between pseudo-random and truly random. A recipe can only stir what you put into it. A lava lamp — or radio static, or an atom deciding when to decay — brings something genuinely new to the table.
“Is that…
infrastructure?”
a little one for you below.
Here is a small wall of our own. Take a snapshot whenever you like; we’ll fingerprint the picture and read a number out of it.
Take a picture. Get a number.
The lamps below are animated. When you press the button we grab every pixel, run it through a cryptographic fingerprint (SHA-256) and turn the fingerprint into a number from 1 to 100. Blink and press again: different picture, different number.
Whenever you’re ready.
A demonstration of the idea, not a security device: our blobs follow a tidy formula, and the unpredictable part is your timing. The real installations photograph real lamps. This site’s own numbers come from your device’s built-in secure source — see how this generator works.
A recipe can only stir what you give it.
Every computer generator is a recipe: feed in a starting number, follow the steps, out comes a long, convincing sequence. But the recipe is deterministic — the same start gives the same sequence, every time — and that is a problem whenever someone else must not be able to guess what comes next. The security of your bank login rests on numbers nobody can predict. A recipe alone can’t promise that. It needs an ingredient from outside the machine.
So engineers go looking for physical processes that are unpredictable in principle, not just in practice, and build hardware to listen to them.
Lamps, static, atoms, light.
Lava lamps. In the mid-1990s three Silicon Graphics engineers patented the idea of photographing a chaotic scene and hashing the picture into a seed; their example was a row of lava lamps. Since 2017 Cloudflare has run the idea at scale, filming a wall of about a hundred lamps in its San Francisco lobby and mixing the video into the randomness that helps secure a large slice of the web. Its other offices contribute double pendulums, a tiny pellet of uranium, rainbow mobiles and, in Lisbon, fifty wave machines.
Radio static. RANDOM.ORG began in 1997 with a $10 receiver from Radio Shack tuned to atmospheric noise — the crackle between stations, driven by lightning around the planet — and went online at Trinity College Dublin in 1998.
Atoms falling apart. Nobody can say when a particular radioactive atom will decay, only how likely it is. John Walker’s HotBits service timed the clicks of a Geiger tube — krypton-85, later caesium-137 — and served the resulting bits free over the web from 1996 until the source was retired on 1 January 2023.
Noise in the chip. Most devices now carry a hardware generator of their own. Intel put its first on a chipset component in 1999, amplifying the thermal jitter of resistors; the RDRAND instruction in its processors since 2012 pulls thermal noise from inside the silicon. Britain’s ERNIE has picked Premium Bond winners from physical noise since 1957 — first electrons through neon gas, and since 2019 quantum light.
Quantum light. The purest sources of all exploit the fact that quantum events are, as far as physics can tell, random all the way down. In 2018 NIST certified 1,024 random bits with a loophole-free Bell test — numbers no theory that forbids faster-than-light signalling could have predicted.
The fingerprint step is the clever bit.
A photograph of lava lamps is unpredictable, but it is also mostly orange. Used directly, it would make a terrible random number. The trick in every one of these systems is the hash: a cryptographic fingerprint function such as SHA-256 that turns any input into a fixed-length scramble where changing a single pixel changes roughly half the output bits. The snapshot gives you something nobody could guess; the hash spreads that unpredictability evenly across every bit. That is exactly what the demo above does, and why the fingerprint looks nothing like a picture.
Then why doesn’t this site use lava lamps?
Because your device already has the equivalent. Operating systems collect timing jitter and hardware noise into an entropy pool and expose it through a secure generator; the browser hands it to us as crypto.getRandomValues(). Lava lamps, radio static and Geiger tubes are extra sources for people who run servers — and wonderful demonstrations. Our number comes from the chip in your pocket. Here is the full path, with a test you can run.
Public randomness, for when strangers must agree.
There is one more flavour. Sometimes randomness must be unpredictable and public — a draw that everyone can verify after the fact. For that there are beacons: NIST’s publishes 512 fresh bits every minute, signed and chained to the pulse before; the League of Entropy’s drand network, launched in 2019, emits a round jointly signed by independent servers every 30 seconds. Both come with the same warning in capitals: never use a public value as a secret key.
Which is the whole subject in one sentence. Randomness is easy to describe and hard to manufacture — and the people who manufacture it well are the ones who know exactly where theirs came from.
No lamps required.
Your device already has a secure source of randomness. The generator uses it.
Pick a random numberWhere we looked things up
- US Patent 5,732,138 (Lavarand) — Google Patents
- Randomness 101: LavaRand in Production — Cloudflare, 2017
- Harnessing chaos in Cloudflare offices — Cloudflare
- The History of RANDOM.ORG
- HotBits: Genuine Random Numbers — Fourmilab
- The Intel Random Number Generator — Jun & Kocher, 1999 (PDF)
- Behind Intel’s New Random-Number Generator — IEEE Spectrum
- GPO ERNIE I — Science Museum Group
- Premium Bonds take a quantum leap — NS&I, 2019 (archived)
- Experimentally Generated Randomness Certified by the Impossibility of Superluminal Signals — arXiv 2018
- Interoperable Randomness Beacons — NIST
- League of Entropy — Cloudflare, 2019