Every outcome in an online casino is produced by a random number generator, and almost every discussion of that fact stops at the acronym. The mechanism is worth understanding properly, because it explains two things players regularly get wrong: why the moment you press the button matters and the moment the reels stop does not, and what the “provably fair” label does and does not establish.
The short version is that there are two entirely different systems in use, they solve different problems, and neither one guarantees the thing most people assume it guarantees.
Pseudorandom versus true random
A true random number generator derives values from physical entropy — thermal noise in a circuit, atmospheric measurement, radioactive decay timing. The output is unpredictable in principle, not merely in practice. TRNGs are slower and are typically used to seed other systems rather than to run games directly.
A pseudorandom number generator is a deterministic algorithm. Given the same starting value — the seed — it produces the same sequence every time. Modern gaming uses cryptographically secure PRNGs, which are designed so that observing any quantity of output gives you no computational path to predicting the next value or reconstructing the seed.
Every commercial slot runs on a seeded cryptographic PRNG, reseeded regularly from a genuine entropy source. This combination is standard because it is fast enough for high-volume play and verifiable enough for certification, and the statistical batteries testing laboratories apply — distribution uniformity, serial correlation, runs tests across tens of millions of outputs — are designed specifically to detect the failure modes these systems can have. Platforms that publish both their certification body and, where applicable, their verification method, Caswino casino among them, let you see which of the two systems below you are actually dealing with.
How a spin is actually generated
The generator does not sit idle waiting for you. It cycles continuously, producing values thousands of times per second whether anyone is playing or not.
When you press spin, the software takes the value present at that instant and maps it through the game’s reel tables — the virtual reel mapping descended from the 1984 patent — to produce symbol positions. The animation that follows is a rendering of a decision already made.
Three consequences follow directly, and each corrects a common belief:
The timing of your press determines the outcome, in the sense that a different millisecond would have taken a different value. But since the cycle rate is far beyond human resolution, this is not something that can be exploited — you cannot aim at a value you cannot perceive.
Stopping the reels early changes nothing. The result was fixed at the press; the stop button only shortens the animation.
There is no memory between spins. The generator’s internal state advances, but the game holds no record of what it paid, and nothing in the system tracks whether a payout is “due”.
Certified RNG versus provably fair
| Property | Certified RNG | Provably fair |
|---|---|---|
| Who verifies | Independent testing laboratory | The player, per bet |
| When | Periodic audit | Immediately after each round |
| What is checked | Randomness quality and RTP accuracy | That the outcome was not altered after the bet |
| Covers the paytable | Yes — RTP is verified | No |
| Requires trust in | The lab and the regulator | Cryptography only |
| Typical use | Regulated operators, major providers | Crypto-native platforms, in-house games |
These are complementary rather than competing, which is the point most often lost. Certification answers “are the numbers genuinely random and does the game return what it claims?” Provable fairness answers “was this specific result determined before I bet, and did the operator leave it alone?”
How provably fair verification works
The mechanism is elegant and worth walking through once, because it is genuinely checkable rather than a claim you have to accept.
Before the round, the server generates a server seed and shows you its cryptographic hash. A hash is a one-way fingerprint: it commits the server to a value without revealing it, and it cannot be reverse-engineered.
You supply or are assigned a client seed, which you can change. A nonce — a counter — increments with each bet.
The outcome is computed by combining these three inputs through a cryptographic function, typically HMAC-SHA256. After the round, the server reveals the original server seed. You hash it yourself and confirm it matches the fingerprint shown beforehand, then recompute the outcome from the three inputs.
If both match, the server committed to that seed before you bet and could not have changed it afterwards. Since your client seed is part of the calculation and the server did not know it when committing, neither party could have engineered the result.
Verification tools are usually built into the platform, and independent third-party verifiers exist for the common algorithms.
What provably fair does not prove
This is the important limitation, and it is routinely overstated in marketing.
Provable fairness verifies that a result was not tampered with. It says nothing whatsoever about whether the game’s odds are reasonable. A provably fair game with a 20% house edge is provably fair — the mechanism confirms the operator honoured a paytable that was heavily unfavourable to begin with.
It also does not cover the payout schedule, the multiplier distribution, or the return percentage. Those are properties of the game design, and the only thing that independently verifies them is the kind of laboratory testing that certification provides.
Nor does it address the operator’s conduct outside the game: whether withdrawals are paid, whether terms are applied consistently, whether the platform remains solvent. A verifiable outcome on an operator that will not pay you is not worth much.
The clearest way to hold both ideas: provable fairness is a strong guarantee about a narrow question. Certification is a weaker guarantee about a broader one. A platform offering both is meaningfully better positioned than one offering either alone.
Practical points
- Check which system applies to the games you play. Third-party provider titles are almost always certified rather than provably fair; in-house crash and dice games are often the reverse.
- If provably fair, change your client seed periodically. It costs nothing and it is the part of the mechanism you control.
- Verify one round. Doing it once, on any game, tells you whether the tooling actually works.
- Read the RTP regardless. Verification confirms the outcome, not the odds — the return figure is a separate check and the more important one.
- Confirm the certification body independently rather than trusting a footer logo, since the badge is the most-falsified element on gambling sites.
- Do not read either label as a statement about payouts. Both concern process integrity, and neither implies a favourable game.
A closing note that belongs in any honest piece on this subject: a verifiably fair outcome generated by a certified generator is still an outcome drawn from a distribution designed to return less than it takes. Set a budget you are entirely comfortable losing, decide your stop point in advance, and step away when you reach it. Gambling is for adults 18+ only, and free confidential support services are available in most countries.
Leave a Reply