Guides Math & Statistics

How Randomness and Fair Draws Work

Pseudo-random versus secure randomness, modulo bias, why naive shuffles are biased, streaks, exact lottery, dice and Secret Santa odds and fair brackets.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page
On this page

Random choices look simple: flip a coin, pick a name. But whether a draw is actually fair depends on how it is done. This guide covers the few ideas behind the random tools: what "random" means to a computer, three classic ways to get it wrong, and the exact odds of some common draws, every one computed.

Pseudo-random versus truly random

Computers produce pseudo-random numbers: a deterministic algorithm that starts from a seed and returns numbers that pass statistical tests. That is fine for games, simulations and picking a restaurant. It is not fine for secrets such as passwords or keys, which need a cryptographically secure generator fed by the operating system's entropy; see Entropy. A fixed seed gives a repeatable sequence, which is useful for testing: the Mock / Fake JSON Data Generator uses one for that reason. For ordinary numbers use the Random Number Generator.

Mistake 1: modulo bias

To pick from 6 outcomes with a random byte (0 to 255), byte % 6 looks fine. But 256 is not a multiple of 6: values 0 to 3 can each come from 43 bytes and values 4 and 5 from only 42, so the first four outcomes are slightly more likely. The fix is rejection sampling: discard bytes of 252 or more and try again.

Mistake 2: a naive shuffle

Swapping each card with a random position among all positions has n^n equally likely paths, which cannot divide evenly among n! orders. With 3 items there are 27 paths over 6 orders, so some orders appear 5 times and others 4, a built-in bias of 25%. The correct Fisher-Yates shuffle swaps position i only with a random position from 0 to i; it has exactly n! paths, so with 3 items every order occurs exactly 1 time. The List Shuffler, Random Team Splitter and Tournament Bracket Generator depend on this.

Mistake 3: expecting randomness to look even

Real random sequences have streaks, and people mistake them for bias. The chance of at least one run of five heads somewhere in 100 fair coin flips is 81%. Flip with the Coin Flip Simulator, roll with the Dice Roller, and let the Random Decision Wheel or Magic 8-Ball Decision Maker settle ties.

Exact odds of common draws

Pick Odds Meaning
6 numbers from 49 1 in 13,983,816 Every combination is equally likely
Two dice total 7 6/36 The most likely total
A run of 5 heads somewhere in 100 flips 81% Streaks are normal, not suspicious
Nobody draws their own name (5 people) 44/120 = 36.7% Why naive Secret Santa draws often need a redo

For the Lottery Number Generator, every ticket has the same chance, so "unpopular" numbers raise only your share of a jackpot, not your odds. In a 3d6 roll, totals run from 3 to 18 with a mean of 10.5; rolling four dice and dropping the lowest gives a mean of 12.24, which is why that method is common for character stats.

Fair groups and matchups

  • Teams: shuffle everyone, then deal round-robin. Ten people into three teams gives sizes 4, 3, 3, as even as possible.
  • Secret Santa: a valid draw has no one drawing themselves (a derangement). With 5 people only 44 of the 120 possible assignments qualify (36.7%); the share approaches 1/e = 36.8% as the group grows (36.79% for 10 people). A good generator builds a valid assignment directly instead of redrawing. See the Secret Santa Generator.
  • Brackets: a single-elimination bracket for n players always has n − 1 matches. With 12 players the bracket is padded to 16, giving 4 byes, and still 11 matches.

Random content and puzzles

Many generators simply pick uniformly from a curated list: the Random Word Generator, Random Quote Generator, Dad Joke Generator, Trivia Question Generator and Writing Prompt Generator. Identity tools combine parts the same way: the Random Name Generator, Baby Name Generator, Username Generator, Acronym Generator, Hashtag Generator and Random Avatar Generator. Puzzle makers use randomness with constraints. A 75-ball bingo card (Bingo Card Generator) draws 5 numbers per column from 15, so there are C(15,5)^4 × C(15,4) ≈ 1.1e+17 different cards. A perfect maze (Maze Generator) is a random spanning tree of a grid: a 3 × 3 grid has 192 possible mazes and a 4 × 4 grid 100,352. The Sudoku Generator and Word Search Generator fill a grid under rules, then check the result.

Common mistakes

  • Using a normal random function for security. Use a cryptographically secure source for tokens and passwords.
  • Using % n on a random range that does not divide evenly. Use rejection sampling.
  • Shuffling by sorting with a random comparator. It is biased; use Fisher-Yates.
  • Redrawing until it "looks random". Real randomness has clumps.

Try these tools

See also

  • Cheat sheet Statistics Formulas Cheat Sheet
    Mean, standard deviation, z-score, confidence intervals, chi-square.
  • Glossary Entropy
    In security, entropy measures how unpredictable something is, such as a password or key, usually expressed in bits.
  • Glossary Pseudo-random number
    A pseudo-random number comes from a deterministic algorithm that starts from a seed and produces a sequence that looks random and passes.
  • Glossary Probability
    Probability is a number from 0 (impossible) to 1 (certain) that measures how likely an event is.

Frequently Asked Questions

Ordinary random functions are pseudo-random: deterministic but statistically fair, which is fine for games. Secure generators draw on hardware and operating-system entropy and are the right choice for passwords and keys.

AdSense Placeholder
Slot: footer_leaderboard