Cryptographic Randomness vs Math.random: How to Generate Secure Passwords and UUIDs in the Browser
Understand the difference between pseudo-random numbers and OS entropy. Learn why Math.random is unsafe for security, how rejection sampling prevents modulo bias, and how to create collision-resistant UUIDs.

Whether you are creating temporary passwords, generating UUIDs for database primary keys, generating session tokens, or shuffling items in a web application, randomness is a foundational building block of software engineering.
Yet in web development, randomness is frequently implemented unsafely. Many developers use Math.random() to generate authentication tokens, reset links, or passwords, unaware that standard browser random functions are completely predictable and unsuitable for security.
This guide explains how computer randomness actually works, why Math.random() should never be used for security-critical tasks, how the Web Crypto API taps into true operating system entropy, and how Synctoolo's Random Generator eliminates mathematical biases.
Pseudo-Random Numbers (PRNG) vs Cryptographic Randomness (CSPRNG)
Computers are deterministic machines. Given the exact same inputs and clock cycles, a computer algorithm will produce the exact same output every single time. To produce random numbers, software relies on two fundamentally different architectures:
1. Pseudo-Random Number Generators (PRNG)
Functions like JavaScript's Math.random() or Python's random.random() are pseudo-random. In modern browser engines like Google Chrome (V8), Math.random() uses an algorithm called xorshift128+.
Xorshift128+ is designed purely for mathematical speed, not security. It takes a starting number (called a seed) and performs rapid bit shifts and XOR operations to calculate the next number in sequence. While the output looks random to human eyes, it is entirely mathematical. If an attacker observes approximately 64 sequential numbers generated by Math.random(), they can reconstruct the internal state of the algorithm and predict every future number with 100% accuracy.
2. Cryptographically Secure PRNG (CSPRNG)
A CSPRNG does not rely solely on arithmetic formulas. Instead, it gathers true physical entropy from the operating system kernel:
- Microsecond fluctuations in hardware interrupt timing.
- Thermal noise from CPU sensors.
- Disk controller response times.
- Keyboard and mouse hardware timing jitter.
This physical noise is mixed into an entropy pool. When you call the Web Crypto API using crypto.getRandomValues() or crypto.randomUUID(), the browser pulls unpredictable bytes directly from this operating system entropy pool. Even with unlimited computing power, an attacker cannot predict future outputs.
The Hidden Trap: Modulo Bias in Password Generators
Even when developers use crypto.getRandomValues(), they often introduce an accidental mathematical flaw called modulo bias. Here is how it happens:
Suppose you want to pick a random character from an alphabet of 62 characters (letters A-Z, a-z, and digits 0-9). A naive developer writes:
// NAIVE (BIASED) IMPLEMENTATION:
const buffer = new Uint8Array(1);
crypto.getRandomValues(buffer);
const randomIndex = buffer[0] % 62; // Modulo bias!
An 8-bit unsigned integer can hold 256 distinct values (from 0 to 255). When you divide 256 by 62, the result is 4 with a remainder of 8:
256 = (4 * 62) + 8
Because of that remainder, the first 8 characters in your alphabet (indices 0 through 7) will map to 5 possible byte values (0, 62, 124, 186, 248), whereas the remaining characters (indices 8 through 61) only map to 4 possible byte values. Those first 8 characters are approximately 25% more likely to be selected! In security tokens and passwords, this uneven distribution weakens password entropy.
How Synctoolo Solves Modulo Bias: Rejection Sampling
To eliminate modulo bias, Synctoolo's Random Generator uses rejection sampling:
function secureRandomInt(maxExclusive) {
const buf = new Uint32Array(1);
// Calculate highest multiple of maxExclusive that fits in 32 bits
const limit = Math.floor(0xffffffff / maxExclusive) * maxExclusive;
let x = 0;
do {
crypto.getRandomValues(buf);
x = buf[0];
} while (x >= limit); // Reject and re-roll if in the unfair remainder
return x % maxExclusive;
}
By discarding the unfair remainder values and re-rolling, every character in your password has an exact, mathematically identical probability of being chosen.
Anatomy of a UUID v4
A UUID (Universally Unique Identifier) version 4 is a 128-bit number formatted as 32 hexadecimal digits separated by hyphens (e.g., f47ac10b-58cc-4372-a567-0e02b2c3d479).
Out of the 128 bits:
- 6 bits are reserved for metadata (4 bits declare version 4, and 2 bits declare variant 1).
- The remaining 122 bits are purely random.
How unique is a UUID v4? The total number of possible UUIDs is 2 to the 122nd power, which is approximately 5.3 x 10^36 (5.3 undecillion). To put this into perspective: if you generated 1 billion UUIDs every second for 100 years, the probability of generating a single collision is less than one in a billion. You can generate instant, RFC-compliant UUIDs using Synctoolo's Random Generator.
Summary Best Practices
- Use
Math.random()only for casual animations, visual particle effects, or board game simulations where security is irrelevant. - Always use
crypto.getRandomValues()for session tokens, passwords, API keys, or verification codes. - Use rejection sampling to prevent modulo bias when picking items from a custom character list.
- Use native
crypto.randomUUID()for distributed primary keys and document IDs.
Tools mentioned in this article
FAQ
Can two users generate the same UUID v4?+
Statistically, no. With 122 bits of pure entropy, the total number of UUID v4 combinations is 5.3 x 10^36. You would need to generate billions of IDs every second for decades to face any realistic collision risk.
Is it safe to generate passwords in the browser?+
Yes, on Synctoolo. Our Random Generator executes entirely client-side using Web Crypto API. The generated passwords and UUIDs never leave your device and are never sent across the internet.
We build and review free, privacy-first tools at Synctoolo.
Keep reading

Convert temperatures between Celsius and Fahrenheit accurately. Learn the 9/5 formula, fast mental math estimation tricks, and key thermodynamic benchmarks.

Connect devices to wireless networks without typing passwords. Discover the underlying WIFI: URI scheme, hidden SSID handling, and WPA3 security standards.