Step 1 Dice, then a computer
Start with the one random source everybody already trusts, then ask what a computer does instead.
Roll some dice
Five dice. You cannot work out the next five from these, and neither can anybody else.
Now a computer, following a recipe
Give a program a word to start from, and watch what happens when you ask it twice.
Predict first — optional
A word, a date, your name. This is what the generator starts from, and it is the only thing it starts from.
Step 2 Two keys. Tell them apart.
Two keys, 32 bytes each — the same length, so neither has any advantage there. One comes from the browser's own random source; one comes from the Step 1 generator, whose starting point is a 4-digit PIN. Then the checks you would think to apply, applied to both.
Predict first — optional
Do those checks do anything at all?
A fair question. Here are the same four checks, run over a generator with a pattern you could see across a room.
Step 3 Guess the seed, take the key
The page has encrypted the same short message twice — once under each key. Only the encrypted bytes are handed to what happens below: not the keys, not the PIN, not the message.
Your guess first
Every attempt, yours or the computer's, is the same four steps: guess a PIN → rebuild the key that PIN produces → try to open the encrypted message → rejected, or opened. Nothing is compared against the real key; the message's own integrity check is what says whether a candidate worked.
Step 2's generator was started at one of these 4 PINs, picked without telling you which. Pick one and watch a single attempt go through those four steps.
Now stop guessing
Predict first — optional
Guessing from a list of 4 was a warm-up: it showed you one attempt, and a real stranger is not handed a four-item list. What they are handed is the shape of the starting point — four digits — and there are 10,000 of those, counting the ones that begin with a zero. The page will try every one against the encrypted message and count out loud.
What this does, and does not, tell you
| What you can see | What it establishes | What it does NOT establish |
|---|---|---|
| The output looks random | There is no pattern a check of the bytes can find | Anything at all about how many keys could have been produced |
| The key is 256 bits long | A ceiling: no more than 2256 values are possible | How many were actually reachable — here, ten thousand |
| The algorithm is a respected one | The arithmetic turning the seed into output is sound | Where the seed came from, which is the whole question |
| The seed was hashed first | The seed was spread evenly across the output | Any increase in the number of possible seeds |
Where this has really happened
Real TLS and SSH hosts have shipped duplicate and guessable keys, with no flaw in the cryptography and nothing visibly wrong in the keys themselves — the generators simply had too little to start from. That is the same failure as the one on this page, at the scale of the internet. Entropy Collapse is the lab that shows it.
Four questions
No score, and nothing is recorded. If one of these is awkward, the explanation is the point.
How this demo checks its own results
Everything above is this page agreeing with itself, which is not worth much alone: a build that got the cipher wrong would produce output that passed every check in Step 2. So the lab also runs a fixed set of cases published by somebody else, in your browser, on arrival.