If you've ever wondered whether an online wheel spinner is actually fair — or whether it could be quietly rigged to favor one entry over another — you're asking the right question. The answer depends entirely on which random number generator the tool uses behind the scenes.
In this explainer, we break down the two main approaches — Math.random() and crypto.getRandomValues() — and explain why the difference matters for classrooms, giveaways, and any context where fairness is non-negotiable.
What "Random" Actually Means in Software
Before we can compare the two, it's worth being clear about a subtle point: true randomness doesn't exist in software alone. Computers are deterministic machines. Given the same starting conditions, they produce the same outputs every time.
So when we say a tool is "random," we really mean one of two things:
- Pseudo-random — the tool uses a mathematical algorithm that produces numbers that look random, but are technically predictable if you know the starting seed.
- Cryptographically secure pseudo-random — the tool uses an algorithm seeded with real-world entropy (hardware timings, mouse movements, keyboard delays), making the output practically unpredictable.
The first category is fine for casual games. The second category is what you want for anything where fairness or security matters.
Approach 1: Math.random() — The Weak Default
Math.random() is the standard random function in
every JavaScript environment. It's built into every browser. It's
fast. And it's what most simple wheel spinners use.
Here's what happens when you call it:
// Returns a pseudo-random decimal between 0 and 1 const value = Math.random(); // e.g. 0.7234819... // Typical use in a wheel spinner: const index = Math.floor(Math.random() * entries.length);
The problem: Math.random() uses an
internal pseudo-random algorithm with a finite seed. It's
technically possible to reverse-engineer the seed by observing
enough outputs — and if you know the seed, you can predict every
future "random" number. This has real consequences in
security-sensitive contexts, and it's why the ECMAScript
specification says Math.random() is "not cryptographically
secure."
For a casual game of "pick who pays for lunch," Math.random() is fine. For a $500 stream giveaway with 1,000 entries, it's a risk — small, but real.
Approach 2: crypto.getRandomValues() — The Secure Choice
crypto.getRandomValues() is the modern standard for
random number generation in browsers. It's part of the Web Crypto
API and produces numbers sourced from the operating system's
cryptographically secure entropy pool.
Here's how SelectAWheel uses it:
function secureRandom(max) {
if (max <= 0) return 0;
const limit = Math.floor(4294967296 / max) * max;
const buf = new Uint32Array(1);
do {
crypto.getRandomValues(buf);
} while (buf[0] >= limit);
return buf[0] % max;
}
There are two important details in this function that make it "fairer than fair":
-
Rejection sampling. The
do/whileloop discards outputs that would introduce modulo bias — a subtle but real distortion that occurs when you take a random number modulo a value that isn't a power of two. Most simple implementations skip this and end up slightly favoring low-index entries. -
Cryptographic entropy. The
crypto.getRandomValues()call itself is backed by the OS. Each call draws from high-entropy sources that an outside observer can't predict or reproduce.
The result: every entry has a mathematically verified equal chance of winning. No modulo bias. No seed predictability. No way to rig it.
Why This Matters for Real Use Cases
Classroom student selection
When you pick a student at random, the outcome is visible to twenty or thirty people. If the pattern repeats — the same three students getting picked first every week — students notice, and trust erodes. Crypto-secure randomness avoids the subtle clustering that weak RNGs can produce.
Stream giveaways and raffles
A giveaway with real prizes creates real stakes. If someone in chat suspects the wheel is rigged, you've lost them — and possibly a chunk of your community. A verifiable, cryptographically secure RNG proves you're running a fair game.
Legal and compliance contexts
Some jurisdictions have begun to require verifiable randomness for
public raffles and prize draws. Using
crypto.getRandomValues() gives you a defensible
technical foundation if you ever need to demonstrate fairness.
How to Tell Which One a Tool Uses
You can verify any tool in about 10 seconds:
- Open the page. Right-click on the wheel and choose "Inspect" or press F12.
- Go to the Sources panel. Look for the main JavaScript file the tool loads.
- Search for "Math.random" and "crypto.getRandomValues". Use Ctrl+F in the source viewer. Whichever one appears in the spin logic is what the tool uses.
-
Bonus check: if the tool uses
crypto.getRandomValuesbut doesn't include rejection sampling, it may still have modulo bias. Look for ado/whileloop nearby.
SelectAWheel uses crypto.getRandomValues() with
rejection sampling. You can verify this yourself in your browser's
DevTools.
The Practical Difference
For a one-time pick between two options, you won't notice any difference between the two approaches. Both will feel random.
But for 1,000+ spins, the difference becomes statistically visible. Weak RNGs can produce subtle clustering — the same few entries winning more often than they should. A crypto-secure RNG with rejection sampling produces a near-perfect uniform distribution.
If you want to see this for yourself, run our wheel 1,000 times and count how many times each entry wins. The distribution should be close to uniform. Some tools let you do this with a "verify randomness" feature; others don't expose it.
Bottom Line
Not all wheel spinners are equally random. The difference comes
down to which random number generator the tool's developers chose
to use. crypto.getRandomValues() is the modern,
secure, and fair choice.
If you're running anything with real stakes — a classroom, a giveaway, a public raffle — it's worth checking that your tool uses it. It's a small detail that makes a big difference.
Author
SelectAWheel Team — we build and maintain the
free SelectAWheel wheel spinner, which uses
crypto.getRandomValues() with rejection sampling.
Reach us at
admin@selectawheel.com.
Try a Provably Fair Wheel Spinner
SelectAWheel uses cryptographically secure randomness with rejection sampling. Verify it yourself in DevTools.
Launch SelectAWheel →