A die is decided by physics. A pseudorandom number is decided by its seed. Is anything decided by nothing at all?
Quantum computers, radioactive decay, the heat in a CPU, pseudorandom generators — ten things we call “random,”
scored with the same four yardsticks and put in order. Number one is the only method where
a theorem guarantees that not even the people who built the device could know the next value.
“Random” means three different things
Before ranking anything, the word needs splitting. When people say “perfect randomness” they mean one of these:
Statistical randomness — the output is unbiased, shows no period, passes the test suites. A pseudorandom generator can do this
Adversarial randomness — no amount of past output lets you guess the next value. A cryptographic generator with a hidden seed can do this (given a computational assumption)
Ontological randomness — the outcome was not determined by any state that existed before the measurement. Only quantum mechanics offers this
In 1814 Laplace wrote that an intellect knowing the position and velocity of every particle could predict the whole future.
In that world, sense 3 does not exist: every “random” thing is sense 1 or 2 — merely unknown.
What Bell showed in 1964 is that, as long as quantum mechanics predicts correctly, that intellect cannot exist:
any theory that fixes measurement outcomes in advance via hidden variables disagrees with experiment.
That is the spine of this ranking. Can we tell “merely unknown” apart from “not yet decided”?
Four yardsticks
Each source is scored 0–5 on each axis. The order is lexicographic — higher axes weigh more — not a sum.
01Freedom from determinismIs the output, in principle, undetermined by every variable that existed before the measurement? 0 is fully deterministic, 5 is a quantum measurement
02Resistance to an insiderCan someone who knows the blueprint, the seed and the full current state still not guess the next value?
03Third-party verifiabilityCan the person receiving the output check that it really was produced this way? Most methods score 0 here
04How little you must trustOf the manufacturer, the operator and the detector, how few do you have to take on faith? Fewer is higher
tier · guaranteed by theorem · NIST Randomness Beacon and others
Even if the device was built by your adversary, a violation of Bell’s inequality proves the output was unpredictable. Today this is the only method that can show a third party that the bits were “not yet decided.”
determinism
5insider
5verifiable
5trust needed
5
HowEntangled particles are measured at two distant stations, with the measurement setting chosen on the spot. If the correlations violate Bell’s inequality, it follows as a theorem that the outcomes were not fixed before the measurement. Since you never need to look inside the apparatus, this is called “device-independent.” 42 bits were certified with trapped ions in 2010; in 2018 NIST certified 1,024 bits from a loophole-free experiment.
WeaknessesSlow (the 2018 run took about ten minutes for 1,024 bits). It assumes the measurement settings were chosen freely — that is, you need a little randomness to certify randomness. What you get is randomness expansion, not creation from nothing. It also assumes no faster-than-light signalling.
Where it belongsPublic lotteries and standards beacons. Not something an individual uses day to day.
tier · certified, under a computational assumption · Quantinuum H2 / 2025
Give a quantum computer a problem no classical machine can fake in time, then check its answers on a supercomputer. The runner-up among methods that prove unpredictability — but the proof rests on the assumption that classical computers really cannot do it.
determinism
5insider
5verifiable
4trust needed
4
HowA verifier sends random quantum circuits; the quantum computer must reply within seconds. A classical computer cannot produce convincing answers in that window, so any convincing reply must contain genuine quantum measurements. Aaronson and colleagues worked out the theory; in 2025 a 56-qubit trapped-ion machine certified over 70,000 bits, with 1.1 exaFLOPS of classical computing spent on verification.
WeaknessesVerification needs a supercomputer. The proof rests on a complexity assumption rather than on physical law. As with #1, the side sending the circuits needs randomness of its own.
tier · quantum, but you trust the device · HotBits and others
When a single nucleus decays is the oldest known “undecided” event in quantum mechanics. But whoever receives the bits can verify neither the source nor the detector.
determinism
5insider
4verifiable
1trust needed
2
HowAlpha decay is a particle tunnelling out of the nucleus; beta decay is a conversion via the weak interaction. For both, “when the next one happens” is only a probability. A Geiger counter timestamps each decay; compare two successive intervals, longer = 1, shorter = 0, one bit at a time (the HotBits method).
Uranium-238Half-life 4.47 billion years. An atom that waits the age of the Earth for half its kind to go, then breaks at one moment, for a reason no one can name. About 12,000 decays per second per gram. Alpha particles stop at a sheet of paper, so the detector sits right against the source.
Potassium-40Half-life 1.25 billion years. It is 0.012% of natural potassium, so a human body carries about 4,000 becquerels and a banana about 15. 89% decays by beta emission to calcium-40; 11% by electron capture to argon-40, releasing a 1.46 MeV gamma ray. Gamma rays leave the body, so in principle you could use yourself as a random source — at a very low count rate.
Americium-241What hobbyists actually use: the source inside an ionisation smoke detector. Half-life 432 years, roughly 37 kilobecquerels each. A tiny dose, but plenty of counts for a random-number generator.
WeaknessesNobody can steer the decay itself, but if the source is swapped for a pseudorandom generator, the recipient cannot tell. Detector dead time drops short intervals and introduces bias. Count rates are low: tens to hundreds of bits per second.
tier · quantum, but you trust the device · ID Quantique Quantis / ANU QRNG
Which way a single photon goes at a half-silvered mirror, or the fluctuating electric field of empty space. Same quantum pedigree as radioactive decay, ranked just below it because classical noise gets mixed in. On speed, it wins by a mile.
determinism
4insider
4verifiable
1trust needed
2
How(a) Send photons one at a time at a beam splitter; transmitted or reflected gives 0/1 (Quantis, a few Mbit/s). (b) Interfere a laser with the vacuum in a homodyne detector and read the vacuum’s quantum fluctuations as a voltage (ANU, several Gbit/s). Method (b) is the one most commercial random-number services use.
WeaknessesIn (a), detector afterpulsing correlates neighbouring bits. In (b), electronic thermal noise rides on top of the quantum fluctuations, so you must measure how much is quantum and extract only that much. Trusting the device is the same problem as #3.
05
Single-qubit measurement on a quantum computer (via the cloud)
tier · quantum, but you trust the device and the operator · IBM Quantum and others
Put a qubit in superposition and measure it. The event is the same quantum measurement as the two above, but readout error runs at a few percent, and there is no way to confirm that real hardware ran on the far side of the API.
determinism
4insider
3verifiable
1trust needed
1
HowApply a Hadamard gate to |0⟩ to get (|0⟩+|1⟩)/√2, then measure. Ideally 0 and 1 come out exactly half the time. Repeat thousands of times for a bit string.
WeaknessesToday’s machines have 1–several percent readout error and the bias drifts day to day, so the raw bits go through an extractor (a hash) rather than being used directly. Above all, if the far side of the API were a pseudorandom generator, the recipient could not tell. Method #2 exists precisely to fix this.
An honest noteThis site’s Quantum Roulette and Quantum Draw use this method. The “seal” they publish prevents the operator from choosing after seeing the result; it is not proof that the source was genuinely quantum. That trust is placed in IBM.
06
CPU thermal noise (Intel RDRAND and other on-chip generators)
tier · physical, but classical · Intel DRNG / AMD / ARM TRNG
Electrons jostled by heat, read by a circuit that could tip either way. In practice nobody can read it, but physically it sits on the “merely unknown” side, and you have no choice but to trust the manufacturer.
determinism
3insider
3verifiable
0trust needed
1
HowIntel’s DRNG deliberately holds a bistable circuit at its midpoint and lets thermal noise decide which way it falls, producing about 3 Gbit/s of raw bits that are conditioned with AES. Thermal (Johnson–Nyquist) noise is the heat motion of electrons; classical physics describes it as deterministic chaos. At the very bottom it is quantum, but as a model it is closer to “too fast to follow.”
WeaknessesYou cannot see inside the chip. In 2013, after reports of NSA interference, Linux decided not to rely on RDRAND alone and to mix it with other sources. In 2019 a bug in some AMD CPUs made RDRAND return the same value every time, and systems failed to boot. “Hardware random” and “trustworthy random” are different things.
07
CPU temperature and timing jitter (sensor readings, interrupt timestamps)
tier · physical, but thin · the OS entropy pool
The low bits of a temperature sensor, the sub-microsecond remainder of a keystroke or disk interrupt. There is jitter, but each event carries little information and it skews with load and environment. Not a source on its own — raw material for a seed.
determinism
2insider
1verifiable
0trust needed
2
HowLinux’s /dev/random collects things like the nanosecond remainder of each interrupt’s arrival time into a pool and hashes the whole pool for output. Temperature sensors are treated the same way: not the value, only the wobble in its lowest bits.
WeaknessesTemperature changes on a scale of seconds and can be estimated by anyone with access to the same machine. Embedded devices that generated keys right after boot, before the pool had filled, produced identical keys found all over the internet (the 2012 large-scale RSA key survey) — a direct consequence of this weakness.
tier · deterministic, but computationally unreadable
Entirely determined by the seed. Yet for anyone without the seed, guessing the next value costs the same as breaking the cipher. In practice this is what “random” means in everyday computing.
determinism
0insider
4verifiable
0trust needed
3
HowTake the seed gathered by #6 and #7 and stretch it with a cipher (a stream cipher or a hash). With a 256-bit seed, no amount of output lets you recover it — as long as ChaCha20 stands.
WeaknessesIf the seed leaks, or was biased, everything is readable. An “insider” by definition knows the seed, so this cannot score full marks. Even so, for passwords, keys and session IDs this is enough, and swapping in quantum bits would not make them safer — the weak point is key storage, not the source.
Passes the statistical tests. But a few hundred outputs let you reconstruct the entire internal state and predict everything that follows. Built for simulation and games.
determinism
0insider
1verifiable
0trust needed
3
HowThe Mersenne Twister (MT19937) keeps 624 32-bit words of state and has a period of 219937−1. Python’s random, older Ruby and many game engines use it. Math.random in V8 (Chrome, Node) is xorshift128+.
WeaknessesMT19937’s state can be fully recovered from 624 consecutive outputs. xorshift128+ can be solved for its seed from a handful of outputs with a constraint solver. “Looks random” and “cannot be read” are different properties.
10
Linear congruential generators (Java’s Random, some C rand() implementations)
tier · deterministic, instantly readable
xn+1 = (a·xn + c) mod m. Two outputs tell you the third. A 1950s method that still lives in textbooks and old libraries.
determinism
0insider
0verifiable
0trust needed
3
Weaknessesjava.util.Random is a 48-bit LCG whose seed is fixed by two consecutive outputs. The low bits have short periods; some implementations alternate odd and even. The 1960s RANDU generator is famous for its triples all lying on 15 planes when plotted in 3D.
At a glance
#
Method
Free
Insider
Verify
Trust
Typical rate
01
Bell test (device-independent)
5
5
5
5
hundreds of bits/min
02
Random circuit sampling
5
5
4
4
tens of thousands of bits/run; supercomputer to verify
03
Radioactive decay
5
4
1
2
tens to hundreds of bits/s
04
Optical QRNG
4
4
1
2
Mbit to Gbit/s
05
Quantum computer, single qubit
4
3
1
1
thousands of bits/job
06
CPU thermal noise (RDRAND)
3
3
0
1
Gbit/s
07
CPU temperature / timing
2
1
0
2
a few bits/event
08
Cryptographic PRNG
0
4
0
3
Gbit/s
09
General-purpose PRNG
0
1
0
3
Gbit/s
10
Linear congruential
0
0
0
3
Gbit/s
The gaps between #3, #4 and #5 are not about “quantum or not.” They are about how much classical noise and how many trusted parties get mixed in. As physics, #3 through #5 are all the same quantum measurement — uranium and potassium-40 stand level there. Rank by speed and the order flips.
In depth — the top three
01 Why a Bell test can prove “not yet decided”
The tool is the CHSH inequality. At two stations (A and B) you choose between two measurement settings each (a, a′ and b, b′), record outcomes as ±1, and compute the correlations E.
S = E(a,b) − E(a,b′) + E(a′,b) + E(a′,b′) If outcomes are fixed in advance by local hidden variables, |S| ≤ 2 Quantum mechanics allows up to 2√2 ≈ 2.83 (the Tsirelson bound)
The core of the proof is arithmetic: assume the outcomes were decided before the measurement, and S cannot exceed 2. So the moment S exceeds 2, it follows that nothing had decided the outcomes in advance. You never need the blueprint of the apparatus because the argument never mentions it. And it is quantitative: the probability that anyone can guess the next outcome is bounded from S alone.
guessing probability ≤ 1/2 + (1/2)·√(2 − S²/4) (Pironio et al. 2010) S = 2 gives 1 (fully predictable); S = 2√2 gives 1/2 (a fair coin, one bit per trial)
The first experiment, in 2010, used two ytterbium ions one metre apart and took about a month to produce 42 bits. In 2018 NIST measured photon pairs at two detectors about 185 m apart, tens of thousands of pairs per second, and certified 1,024 bits from 55 million trials in ten minutes, within 10−12 of uniform.
It is called “loophole-free” because three loopholes were closed at once:
Locality — each measurement must finish before the other station’s setting choice could arrive. 185 m is 0.6 microseconds at light speed; choose, measure and record inside that window
Detection — if the photons you failed to detect were biased, the survivors alone could appear to violate the inequality. Superconducting nanowire detectors with efficiency above 90% close this
Freedom of choice — if the settings were correlated with the particles, nothing follows. Settings come from independent random sources. The 2017 “Big Bell Test” used 0s and 1s typed by 100,000 people on their phones; another experiment set the measurement basis from the colour of quasar light emitted billions of years ago
The raw bits are not uniform, so a Trevisan extractor evens them out at the end — and that needs a short random seed of its own. The accurate name is therefore randomness expansion (or amplification), not creation from nothing.
02 What random circuit sampling actually proves
The protocol formalised by Aaronson and Hung in 2023 is a dialogue.
The verifier (you) generates circuits C1, C2, … from randomly chosen quantum gates and sends them
The quantum computer runs each one and returns a measured bit string xiwithin a fixed short deadline
The verifier computes each circuit’s ideal output distribution on a supercomputer and scores how “genuine” the returned xi look
XEB = 2n · mean( |⟨xi|Ci|0…0⟩|² ) − 1 ≈ 1 for an ideal quantum computer, ≈ 0 for made-up answers
The argument: for a classical computer to score well it would have to compute the distribution after receiving the circuit, which (by assumption) takes orders of magnitude longer than the deadline. So if high-scoring answers came back in time, they were not the product of classical computation — they contain real quantum measurements, and those are unpredictable. From the score and the response time one can compute a lower bound on the randomness contained (the min-entropy).
The 2025 experiment (Liu et al., Nature) sent circuits over the internet to Quantinuum’s 56-qubit trapped-ion machine H2-1 and scored the replies on four supercomputers — Frontier, Summit, Perlmutter and Polaris, 1.1 exaFLOPS combined — certifying 71,313 bits. It is one of the first claims of a practical quantum advantage.
How it differs from a Bell test:
The assumption is computational, not physical — if “no classical machine can do it in time” fails, the proof shrinks. Every time classical simulation gets faster, the same data certifies fewer bits
It is a proof for the verifier only — a third party who wants to be convinced must re-score the same circuits on their own supercomputer. A Bell test’s S value means the same thing to everyone
You trust the verifier’s clock — “it came back in time” is measured on the verifier’s side. Break that and the proof vanishes
It still needs randomness — the circuits must be random, and that randomness comes from the verifier. Like #1, this is expansion, not creation
Even so, it is the only known way to check the far side of a quantum-computing cloud. The weakness of #5 — “you cannot tell if the API is backed by a pseudorandom generator” — is solved by this protocol and nothing else.
03 Why nothing fixes the moment a uranium-238 nucleus breaks
Uranium-238 makes up 99.27% of natural uranium and has a half-life of 4.468 billion years. The crust holds about 2.7 ppm, seawater 3.3 ppb, and a human body roughly 90 micrograms. It emits an alpha particle (mostly 4.20 MeV) to become thorium-234, then falls through a 14-step decay chain (8 alphas, 6 betas) to settle as lead-206 over some 4.5 billion years.
decay constant λ = ln 2 / T½ = 4.9 × 10−18 per second (the chance one atom breaks in the next second) 1 g of U-238 = 2.5 × 1021 atoms → about 12,400 decays per second
Gamow explained why it breaks at all in 1928. The alpha particle (two protons, two neutrons) is held inside the nucleus by the strong force; to leave, it must cross the Coulomb barrier, a wall some 25–30 MeV high. But the alpha carries only 4.2 MeV. In classical physics it can never get out. In quantum mechanics the particle leaks slightly into the wall, and each time it strikes the wall there is a tiny chance it passes straight through (tunnelling).
alpha strikes the wall ≈ 1021 times per second chance of getting through per strike ≈ 5 × 10−39 multiply: λ ≈ 5 × 10−18 per second → half-life 4.5 billion years
The beauty of the formula is that the escape probability depends exponentially on the height and thickness of the wall. A slightly more energetic alpha shortens the half-life by many orders of magnitude: polonium-212 (8.8 MeV) lives 0.3 microseconds, uranium-238 (4.2 MeV) 4.5 billion years — twice the energy, a factor of 1023 in half-life. This is the Geiger–Nuttall law, and it holds as a single straight line across 24 orders of magnitude.
Now the “when.” Each strike on the wall is an independent trial, so the decay time follows an exponential distribution, which is memoryless. A uranium atom that has survived 4.5 billion years has exactly the same chance of breaking in the next second as one made a moment ago. The atom does not age. If it carried an internal clock counting down, older atoms would be more likely to go, and that is not what is observed. So the grounds for “not yet decided” are not that no clock has been found, but that a clock would change the statistics, and the statistics do not change.
In fairness: a single atom’s decay has no equivalent of a Bell test. Method #1 settles the matter with a theorem — hidden variables cannot violate the inequality — whereas the indeterminacy of decay rests on trusting that quantum mechanics is correct. That is half the reason it is ranked third (the other half is having to trust the source and the detector).
The actual procedure for extracting bits:
Place the source against a Geiger tube (or scintillator) and timestamp each decay to microsecond precision
Compare two successive intervals t1, t2: 0 if t1 < t2, 1 if t1 > t2, discard ties. The slow decline of the source cancels out (the HotBits method)
Detector dead time drops short intervals, so any remaining bias is removed with von Neumann’s trick (01→0, 10→1, discard 00 and 11) or a hash
Uranium-238 itself is rarely the practical choice: its alphas stop at a sheet of paper and the count rate is low. HotBits used krypton-85 and later caesium-137. Hobbyists use the americium-241 from a smoke detector, or uranium glass and ore specimens, which are legal to buy. With uranium the chemical toxicity of a heavy metal becomes a problem before the radioactivity does — never inhale the dust or put it in your mouth.
Reflection — it takes randomness to certify randomness
Even #1 has an assumption: that the measurement settings were chosen freely. If the initial conditions of the universe had lined up the experimenters’ choices with the particles’ states in advance (superdeterminism), a Bell violation would prove nothing. No experiment can close this loophole, so physicists state the result as an expansion: if the randomness used for the choices is even slightly genuine, the output is more so. No method yet makes randomness out of nothing.
One more. That a particular bit string “is random” cannot be proved, even in principle. Its Kolmogorov complexity — the length of the shortest program that prints it — is uncomputable, and Chaitin showed there is a ceiling on the length of any string that a formal system can prove incompressible. So a proof of randomness is always a proof about the procedure, not the string. What #1 certifies is not “these 1,024 bits” but “the process that produced these 1,024 bits.”
And in practice something matters more than the ranking. When people doubt a lottery or a trial randomisation, the doubt is not “was the source quantum?” but “did the operator look at the result and swap it?” What prevents that is not the quality of the source but a procedure: seal first, publish the hash. A #8 pseudorandom draw with that procedure deserves far more trust than a #5 quantum draw without it.
Which one to use
Passwords, encryption keys, session IDs→ 08 The OS cryptographic generator is enough. Quantum bits would not make it stronger; the weak point is how the key is stored, not where it came from
Simulation, games, initialising machine-learning models→ 09 Being able to fix the seed for reproducibility is the whole point. Nobody is trying to predict it
Draws and randomisation that other people will scrutinise→ procedure + 03–05 Seal first, publish the hash. The source need not be quantum, but if you want to say “this was decided by nothing,” use one that is (Quantum Draw, Verifiable Randomisation)
Standards, public beacons, papers that need a proof→ 01 · 02 Cite the NIST beacon or a device-independent experiment
Touching something undecided with your own hands→ 03 The americium in a smoke detector and a Geiger counter. Or count the potassium-40 in your own body
Sources
J. S. Bell, “On the Einstein Podolsky Rosen paradox,” Physics 1, 195 (1964).
S. Pironio et al., “Random numbers certified by Bell’s theorem,” Nature 464, 1021 (2010).
P. Bierhorst et al., “Experimentally generated randomness certified by the impossibility of superluminal signals,” Nature 556, 223 (2018). NIST loophole-free Bell test, 1,024 bits.
M. Liu et al., “Certified randomness using a trapped-ion quantum processor,” Nature 640, 343 (2025). Quantinuum H2, 56 qubits, 71,313 bits.
T. Symul, S. M. Assad, P. K. Lam, “Real time demonstration of high bitrate quantum random number generation with coherent laser light,” Appl. Phys. Lett. 98, 231103 (2011). The ANU vacuum-fluctuation QRNG.
M. Herrero-Collantes, J. C. Garcia-Escartin, “Quantum random number generators,” Rev. Mod. Phys. 89, 015004 (2017). Review of methods.
Intel, “Digital Random Number Generator (DRNG) Software Implementation Guide.” Thermal-noise source and conditioner design.
N. Heninger et al., “Mining Your Ps and Qs: Detection of Widespread Weak Keys in Network Devices,” USENIX Security 2012. Duplicate keys from boot-time entropy starvation.
M. Matsumoto, T. Nishimura, “Mersenne Twister,” ACM TOMACS 8, 3 (1998). 624-word state, recoverable from output.
G. J. Chaitin, “Information-theoretic limitations of formal systems,” J. ACM 21, 403 (1974). Limits on proving incompressibility.
S. Aaronson, S.-H. Hung, “Certified randomness from quantum supremacy,” STOC 2023. Theory of certification by random circuit sampling.
G. Gamow, “Zur Quantentheorie des Atomkernes,” Z. Phys. 51, 204 (1928). Alpha decay as tunnelling.
The BIG Bell Test Collaboration, “Challenging local realism with human choices,” Nature 557, 212 (2018).
P.-S. Laplace, Essai philosophique sur les probabilités (1814).
Half-lives and specific activities from NNDC (Brookhaven) nuclear data; body potassium-40 is an estimate from the ICRP reference-person model.