9 ms·
“True” Randomness vs. “Pseudo” Randomness
- acidburnNSA 4y agoI had a fun time rigging my Geiger counter up to my computer for a little demo project of getting random numbers from radioactive decay. It's stupidly slow as is, but could be sped up. I should hook it up to my sound card multichannel analyzer and scintillator now that I have one and update this. Would be way faster with more pulses coming in from the lower-energy gammas and x-rays that the G-M tube can't see. https://partofthething.com/thoughts/making-true-random-numbers-with-radioactive-decay/ https://partofthething.com/thoughts/making-true-random-numbe...
- mikequinlan 4y agoI haven't read the article yet, but I want to say that (so far) this is no actual proof that radioactive decay is random. There is evidence for it, and we assume it is, but it hasn't been proven.
- acidburnNSA 4y agoTrue. There's a whole debate about determinism in the universe, which includes radioactive decay. It's just one of those things that's considered roughly as random as it gets.
- cycomanic 4y agoThat's not really true. The Bells inequality experiments have proven (falsified) that there are no local hidden variables. The vast majority of scientists are not willing to throw away causality by accepting nonlocal hidden variables. In other words the true randomness of quantum Events has been broadly accepted to reflect reality.
- dahart 4y agoThe article agrees, but of course it’s making a slightly different point and talking about what kinds of randomness are practically or even theoretically predictable today given what we know. Since nobody knows how to predict radioactive decay, it’s currently considered “truly” random, but its status could change in the future. “Arguably then, from a truly omniscient perspective, nothing, not even the physical world, is truly random—it is in the nature of causality that everything that happens has a chain of prior events that caused it. But in practice, for most real-world randomness, obtaining such an omniscient perspective is infeasible to the point of being impossible.”
- SideQuark 4y agoThere can be no proof, in the mathematical sense, of anything about the physical world, so radioactive decay being provably random in the most tested, accurate model of the world we have is as close to certainty as anything known about the physical world. Semi-related is this year's Nobel Prize for experiments showing Bell's Theorem is physically true. This rules out hidden variable theories.
- amelius 4y agoHmmm. First you say that there can be no proof of anything about the physical world. Then you tell about a Nobel prize for showing Bell's Theorem is physically true ...
- Timon3 4y agoYou left out the parts which answer your question. GP specifically wrote: > There can be no proof, in the mathematical sense, of anything about the physical world[...] followed by: > Semi-related is this year's Nobel Prize for experiments showing Bell's Theorem is physically true. The first quote refers to "mathematical proof", the second to "physical proof". They are different categories.
- amelius 4y agoOk, what is a physical proof then, apart from strong evidence?
- atoav 4y agoPhysical proof is not the same as mathematical proof. It is strong evidence for a mathematical model to be an adequate description of reality. But that means we did not proof that the mathematical model is reality. There might be some weird edge case looming around the corner under which our model utterly fails to describe the physical world. Then we have to adjust the model or find a new one.
- icegreentea2 4y ago
- mattpallissard 4y ago> Arguably then, from a truly omniscient perspective, nothing, not even the physical world, is truly random Technicality or practicality? This is one of those mathematician vs engineer topics. I'm reminded of this lkml thread from a few years back. https://lwn.net/ml/netdev/CAHk-=wiSw7zYVUxiGT=_TPx1fqtNNYgu0L6rC=GaSGpCDnDbVw@mail.gmail.com/ https://lwn.net/ml/netdev/CAHk-=wiSw7zYVUxiGT=_TPx1fqtNNYgu0...
- valine 4y agoEven from an omniscient perspective it isn’t remotely clear that quantum waveform collapse isn’t entirely random. Quantum random number generators should be empirically nondeterministic.
- oconnor663 4y ago> High-quality algorithmic randomness is similar. If we are denied an omniscient perspective—if we can't look “inside the box” to see what is going on—the random numbers produced will seem completely random. The article touches on this briefly, but I think the distinction between cryptographic pseudorandomness and (unfortunately) "ordinary" pseudorandomness is important here. To get at the difference, we could say that you're allowed to look at everything inside the box, except specifically the bits of the secret seed. If there's still no way for you to distinguish the output from true randomness, other than the "brute force" strategy of trying every possible seed value, then this box gives you cryptographic randomness (i.e. it's a "CSPRNG"). Usually we'd also want to make the seed big enough that we don't have to worry about that brute force attack in practice, 256 bits as a rule of thumb. > They would then use their spy-craft to combine their message with the random numbers (e.g., by numbering the letters of the alphabet and adding each successive letter of their message to each successive number from the table). They could then send that message knowing that if it was intercepted, it would be unreadable without a copy of their codebook (I'm sure the author understands the following, but I think it's important to clairfy it anytime we touch on encryption.) This sort of scenario is tricky if we don't make the "cryptographic vs ordinary" distinction above. There are lots of PRNGs that look random to us but whose output can be fully predictable to a computer program after a few observations. This isn't a rare corner case: most PRNGs have this issue unless they're speficially designed not to. For example, the Mersenne Twister algorithm used by Python's `random` module has this property, and I think the PCG algorithm that this article is about also has this property. If you use Python's `random.randbytes()` to generate your codebook, it's entirely possible and arguably likely that someone reading your encrypted messages will learn enough to predict every subsequent page of your codebook, which lets them easily decrypt all your messages after a certain point.
- fwlr 4y agoThe PCG family is somewhat harder to predict than Mersenne Twisters, but not nearly as hard to predict as cryptographic PRNGs. PCG’s author goes into some detail about it here https://www.pcg-random.org/predictability.html https://www.pcg-random.org/predictability.html and the conclusion is: “ The PCG family is designed with being difficult to predict in mind, and the default generators are not trivially predictable. But the primary design goal for most members of the PCG family is to be a fast statistically-good general purpose generator, and so by design they do not work quite as hard as most cryptographically secure generators. “Most of the PCG output functions involve nonlinear operations and only reveal partial state, but as we saw from Knuth's truncated LCGs, that's no guarantee of that PCG generators can't be cracked.”
- transitivebs 4y agotwo of the best PRNG libs for JS/TS: https://github.com/transitive-bullshit/random https://github.com/transitive-bullshit/random and https://github.com/stdlib-js/stdlib https://github.com/stdlib-js/stdlib
- 11thEarlOfMar 4y agoOne time, my wife and siblings had to choose from a number of heirlooms that had be left to them but not assigned. They are living around the planet, and the discussion came up about how to decide the order in which they'd select the items. I came up with this: Each of them select a different stock market index. On the same calendar trading day, they choose two digits past the decimal. When the market's close, compare the two digits of the closing price of their chosen index to the two digits they selected and then choose heirlooms in the order of closeness. It worked quite well. They were on board because they could make two selections in determining their order: Market and digits. Two of them could choose the same two digits if they wanted and still have different scores. No complaints. Not random, but seemed fair to all.
- mcstafford 4y agoOne thing we seem to have discovered is that absolute randomness is harder than it might first seem. Your idea combines what feels like a significant percentage of randomness while still having enough participation to rationalize buy-in. It's tough to want to yield control of an important choice to a random number generator... though that's not an inaccurate description for this. I like this as a perspective on "the illusion of choice". Part of me hates the phrase because I want to believe that I can take meaningful action.
- pwython 4y agoThis is one of the craziest, most convoluted approaches to randomness I've ever heard of. I love it. Personally, I would've just had a third-party roll a die to establish the order. If there's a tie, roll again. More than 6 siblings? Two dice. Fun for the whole family! (and would take just a few minutes)
- oconnor663 4y agoKeybase supports provably fair coin flips :)
- thrashh 4y agoI don’t think the issue was the randomness. I think it was avoiding trusting a third party.
- rramadass 4y agoThis article touches a nerve for me since i have always wanted to better understand (ever since exposed to books by Ivar Ekeland and Nassim Taleb) the relation and differences between concepts like Random, Probability, Stochastic, Pseudo-Random, Determinism/Non-Determinism, Chaos, Information, Entropy. I would really appreciate it if folks can point me to books/papers/articles/etc. which explain all of the above starting from first principles. Also are there any courses one can pursue to study the above?
- cratermoon 4y agoApplied Cryptography: Protocols, Algorithms, and Source Code in C, by Bruce Schneier
- tptacek 4y agoNot a good book for this at all. I don't think I'd start with cryptography if what I was really after was stochastic processes; something in algorithms would be better. But a good modern starting book for cryptography is JP Aumasson's Serious Cryptography.
- Exuma 4y agoAfter this article I went and started reading about "roulette computers" and apparently there are 50+ sites owned by a single scammer, that all have the same layout: https://www.roulette-computers.com/ https://www.roulette-computers.com/ And apparently he owns this network of forums and review sites that all funnel towards this scam. Very interesting... It's like as 100x worse than mattress reviews it looks like I wonder if there is an actual legitimate roulette computer that exists (which is mentioned in this randomness article). Maybe the scammer made this post on PCG-Random ...
- version_five 4y agoTheres a summary here: https://www.forbes.com/sites/startswithabang/2017/05/23/how-physicists-used-science-to-beat-the-odds-at-roulette/ https://www.forbes.com/sites/startswithabang/2017/05/23/how-... Apparentl Claude Shannon was even involved in such a scheme. I'd take the article with a grain of salt, but it suggests it's possible.
- jcgrillo 4y agoThis book was a fun read: https://en.wikipedia.org/wiki/The_Eudaemonic_Pie https://en.wikipedia.org/wiki/The_Eudaemonic_Pie
- cratermoon 4y agoThis article's argument boils down to Newtonian physics being, in theory, completely deterministic, thus not "true" randomness. It says, "tools exist to predict the path of a roulette ball (using data gained after it has been released and before the croupier calls, “No more bets!”), at least according to people who make money selling such gizmos". Key phrase there is according to people who make money selling such gizmos. It leaves quantum randomness for a footnote, after spending many words saying that if you use a big enough permuted congruential generator, it's random enough for cryptographic use.
- dghughes 4y agoMy former job of a slot machine tech would often involve setting up a slot machine. The PAR (paytable and reel) sheet had set groupings you could pick. Integrity and Compliance, local government regulators, security, management, superiors, surveillance all watching me like a hawk while I enabled it then seal the chips. edit: just a note that for years I wasn't even allowed to see or touch a PAR sheet. Literally, not even see or touch the things. They were securely locked up. Much of a slot machine is "random" but to a point where the house never lost. If it were truly random not pseudo random there would be no way to control what was won or maybe nobody would win at all. Organized chaos really. And most of the time the slot is a 10 or even 20 year old barely functioning piece of junk. The machine has been paid off (so to speak) so any money it makes is pure profit.
- andy800 4y agoThe outcome of each individual spin is random. The reason a slot machine is always profitable is due to the payouts. To put it simply, a result that will occur once every 100 spins only pays out 90 credits. The various PAR sheets allow casinos to adjust how much to tilt the odds in their favor. For the 1 in 100 example, the various pay tables might have that particular outcome pay 87, 89, 91 or 94 credits, allowing a casino to decide between 6% all the way up to 13% hold. But that particular combination of reels will still occur only 1 in 100 spins (theoretically, because it is in fact random, not cycling through a script).
- riceart 4y ago> If it were truly random not pseudo random there would be no way to control what was won or maybe nobody would win at all. This doesn’t make much sense. You don’t need to manipulate an RNG to ensure the house has an edge - and to my understanding this is generally not done in the big casino venues because it’s not even necessary. Because what you’re essentially suggesting is that machines purposely use poor quality PRNGs - which is absolutely not true. They have in the past unintentionally and have only been burned by it. Utilizing a PRNG does make auditing easier though. And it’s much easier to produce a reliable PRNG than find a reliable source of randomness that is not vulnerable to manipulation. (Having said that, mechanical real machines got by for years without any algorithmic RNG) Games of chance that utilize effectively true randomness (since the behavior is unpredictable even to the house) have been around for millennia.
- prng2021 4y ago“Arguably then, from a truly omniscient perspective, nothing, not even the physical world, is truly random” Super misleading statement, especially with the accompanying footnote. Quantum physics indicates there really is true randomness in the physical world, but let’s just ignore that, stick to Newtonian physics, and throw in a quick footnote to cover ourselves.
- ravi-delia 4y agoCollapse posits truly random events, but there are many deterministic theories. In the end it doesn't really matter though- even if apparent collapse is caused by decoherence, you still subjectively experience winding up in one of them. There are other theories (Bohm comes to mind) that are entirely deterministic without decoherence, but they rely on a random seed and non-local hidden variables.
- tetha 4y agoOne example for using algorithmic over true randomness comes up in games. For example, if the entire map generation is driven by a single RNG instance with a user-chosen (or, initially chosen off of true randomness), players can share seeds generating interesting worlds. Or, even more interesting, folks are brute-forcing Slay the Spire seeds in order to find cool seeds involving a relic called Pandoras Box, which replaces your entire starting hand. From there on, it becomes a very conscious decision how many RNGs to manage in an engine. Unpredictable things, like UI or random animation choices and such tend to have their own RNG, so something like the AI or story-driving systems can have their own, more predictable RNG. However, this again raises a tricky follow-up question: Do you persist the RNG state in the save file of a user? The answer here isn't as obvious as it seems, as it allows different kinds of save-game abuses. Re-initializing the RNG on load allows players to reload in order to get different results from actions. Persisting the RNG allows players to start testing and predicting actions after loading the game. It's a tricky question. Another really interesting tangent to go on here as well is how the NES and similar old consoles handled randomness: They didn't really. The randomness was based on player inputs. This in turn gives raise to a great TAS technique: RNG manipulation. Carefully crafting input sequences can optimize the random results you get later, which results in entirely crazy runs. It's a very interesting topic overall.
- kimburgess 4y agoThis use case (and the associated challenge of deterministic ordering of PRNG calls in distributed systems) is something that’s talked about in the AoE dev writeup: https://www.gamedeveloper.com/programming/1500-archers-on-a-28-8-network-programming-in-age-of-empires-and-beyond https://www.gamedeveloper.com/programming/1500-archers-on-a-...
- Proven 4y ago[dead]
- danbmil99 4y agoI'll just put this here. https://www.oreilly.com/library/view/the-art-of/9780470503829/simo_9780470503829_oeb_c01_r1.html https://www.oreilly.com/library/view/the-art-of/978047050382...
- night-rider 4y agoIs it possible to gather entropy from weird sources from the user like mouse movements, that person's timezone, OS version and type, language preferences, screen resolution, browser fingerprint etc? How would that be any different than atmospheric noise or die rolls? Are people's mouse movements and browser fingerprints that predictable, because last time I checked, people have a certain cadence by the way they move their mouse and the way they type, and browser fingerprinting yields very unique data which is hard to replicate and reproduce.
- inetknght 4y ago> Is it possible to gather entropy from weird sources from the user like mouse movements, that person's timezone, OS version and type, language preferences, screen resolution, browser fingerprint etc? User mouse movements, maybe. But only while it's moving. A person's timezone, OS version and type, language preferences, screen resolution, browser fingerprint etc... those don't change so often. So they're not really good sources of entropy.
- Connor_Creegan1 4y ago[flagged]
- searealist 4y agoShe has time to write blog posts, but claims she doesn't have a few minutes to update the lying front page that makes claims like pcg having just as good prediction difficulty as chacha20 and other misleading entries.