On 29 April 1947, RAND starts up an electronic roulette wheel. A random frequency pulse source, some hundred thousand pulses per second, is gated once per second by a regular pulse. The result passes through a five-place binary counter. The machine produces one number per second. The millionth digit is reached on 7 July.
During production, the ratio of even to odd digits drifts. The machine is heating up. Cooled and restarted, it stops biasing.
The unpredictability of the apparatus depended on its temperature.
The tests then run on the table still find biases, small but statistically significant. The digits are scrambled by modular arithmetic before printing. What appears in 1955 from The Free Press is therefore not the output of the machine. It is that output reworked so as to pass the trials it was about to be put through. The most widely used table of random numbers of the century is a corrected artefact, printed, paginated, and rigorously identical in every copy.
This is not a failure on RAND's part. It is the structure of the operation.
A system that needs the unpredictable cannot establish its presence. Unpredictability is not a property observable in an output: no finite sequence carries it, and every sequence is equally improbable. What the system obtains instead is a document asserting that the output is unpredictable. That document is what it consumes.
The device that produces the document is a bench of tests.
In 1956, the British Post Office Research Station at Dollis Hill builds ERNIE. Harry Fensom designs it in Tommy Flowers's department, the team is led by Sidney Broadhurst, the men who had built Colossus. The machine draws its digits from thermal noise, from the movement of electrons through neon gas. First draw in June 1957, top prize one thousand pounds.
The numbers ERNIE produces are not valid. They are sent to the Government Actuary's Department, which subjects them to frequency tests, serial tests, poker tests, correlation tests. The draw exists once the office has signed. For seventy years the Crown has not been paying out the winnings of a random draw: it has been paying out the winnings of a draw certified compliant.
The gap between the two is measurable, and it runs against randomness. A statistical test at level α rejects, by construction, a proportion α of perfectly random outputs. The Government Actuary's Department applies several, which raises that probability. The certification procedure therefore refuses impeccable draws on a regular basis, and accepts without reservation a table corrected to please it.
The test does not measure randomness. It measures resemblance to randomness.
The contradiction becomes operational as soon as the draw carries a consequence.
A randomised clinical trial demands two incompatible things of its allocation sequence. It must be recorded, retained, reproducible, failing which the trial cannot be audited and its results are worth nothing. And it must remain unknown to the clinician enrolling the patient, failing which they will choose which patient gets which arm, and the randomisation ceases to exist. The methodological literature does not treat this as a detail of protocol: it documents the deciphering techniques, envelopes held up to a lamp, opened out of sequence, series guessed. Concealment is not a precaution added to the draw. It is what makes the draw have taken place.
Auditable means recorded. Functional means unknown. Both are required, and they exclude each other.
It remains to be seen where the attack lands. In 2007, NIST standardises a pseudo-random generator built on elliptic curves, Dual_EC_DRBG. That same year, at the CRYPTO rump session, Shumow and Ferguson show that whoever knows the secret relation between two points on the curve can, from the observed output, reconstruct the internal state and predict what follows. The 2013 documents confirm the suspicion. NIST stops recommending it, then withdraws it from the standard.
Nobody touched an entropy source. Someone wrote a standard.
A system guards its generators, armours its machines, films its draws, and the certification that underwrites all of it becomes the cheapest attack surface, because it is the most centralised and the least inspected. The certificate is not the proof of randomness. It is the single point of failure of randomness.
It remains to ask why institutions hold to it so firmly. What a draw distributes is not luck. Conscription by lottery, the composition of a jury, the allocation of social housing, the selection of a tax audit, the distribution of an organ: in every case the system needs the loser to accept the loss. Randomness is the only known device that produces a decision without a decider.
Drawing lots does not produce a just decision. It produces a decision nobody has taken.
That function is what the certificate protects, not a physical property. Certification does not serve to establish that the digits were unpredictable. It serves to guarantee that nobody can be held to account for the result. What RAND corrected before printing, what the actuary signs every month, what the standard was meant to seal, is the absence of an author.
Doctrine
A system never consumes a property of the world. It consumes a document attesting to that property. The gap between the two remains invisible for as long as the document holds, and it is the document, not the property, that gets attacked.
Unpredictability is the only property that destroys itself in being proved. Every proof demands a trace, every trace is reconstructible, and what is reconstructible is predictable. A certificate of randomness therefore does not attest randomness. It attests the conformity of an output to what is expected of a random output, which is the opposite.
What a draw distributes is not luck, it is unattributability. A system turns to randomness when it needs a consequence that nobody can be charged with. Certification protects that function. The physical property is merely its alibi.
Open vector
On 12 April 2018, a NIST team publishes a draw whose guarantee no longer rests on an apparatus. It rests on a prohibition: the impossibility of transmitting a signal faster than light. The bits produced are certified unpredictable because the alternative would require a violation of relativity.
The displacement is clean. An apparatus can be opened and inspected. A standard can be reread. An actuarial office can be audited, and captured. A physical prohibition cannot be audited, only granted. The certificate gains in solidity exactly what it loses in examinability.
Every draw with a consequence produces a loser, and a loser looks for something to turn against. Against RAND's machine, one could invoke its temperature. Against ERNIE, the actuary who signs. Against the 2007 standard, the institution that wrote it. When the guarantee of a draw no longer belongs to an institution but to a law of nature, what does the loser turn against?
