It's as random as much it can be made so in that range of 2,147,483,647? I'm not a programmer I'm not sure how a stop symbol or blank is chosen when programming a slot theme.
Newer slots are 64-bit and have larger virtual reels.
Some slots now even use a product called quantum randomness supposedly true randomness. https://comscire.com/
Based on the article it seems that the flaw is that the machine uses the timing of human interaction as a significant seed source. This works well enough for unaware people, but as evidenced here is super easy to exploit once the knowledge is out there. Using time (e.g. the time the program started) as the PRNG seed is a very common security flaw. Otherwise experienced engineers keep making this mistake even in 2017.
We can probably agree that PRNG is a function that takes an input and produces an output. I guess you take issue with me calling this input the seed. My use is probably a simplification indeed, but I thought one that doesn't change any principles. Because the user's interaction timing is crucial, it seems pretty clear to me that the exploit is about influencing the input of the PRNG. We can call this input something else, e.g. internal state. Or we can call it the seed.
This way, the spins are selections from a stream. If you take a number of samples you can guess the position in the stream and then calculate the most advantageous time to run another spin. The inputs are probably read on a 60hz timer anyway so you can predict which time you're going to get within a few ticks.
There's little to no excuse for these slot machines not including at least a crude quantum noise collection circuit. Collecting quantum noise in a circuit is nothing exotic and only requires a hand full of transistors and a couple of capacitors. I'm a bit sad that ARM didn't include a quantum noise instruction in the basic arm64 instruction set.
On a side note, it's a shame that WiFi and BlueTooth chipsets don't all have a linear feedback shift register accumulating radio noise. They're already measuring noise and detecting bit errors. With only a few extra transistors, they could be made to expose radio noise to the kernel for use in /dev/urandom and friends.
The successful electronic slot machine hacks in the last 35 years have all involved either measuring internal machine states or modifying the machines.
In this case, the machines were modified to allow profitable play. This is done either to sell the machines to naive casinos (which is what the Russians did in this case) or to casino managers who use them to skim (the manager's confederates win money which need not be reported to casino owners or tax authorities).
Another practice is to modify machines to extract the maximum amount from players, exploiting behavioral tendencies, rather than giving random payouts as required by regulation in most jurisdictions. Advantage gamblers sometimes discover these machines and use the knowledge to play profitably. But it's not enough to observe a few dozen outcomes, you need to know something about how the payoffs are structured.
You won't find these machines in Nevada, because (a) the regulators are smart and powerful and (b) the place is too big a gold mine to risk over small increases in slots revenue. But there are lots of places with inattentive or weak regulators, in which slots is the whole ball game.
Sort of random since it's pseudo random number generator but there is a specific payback percentage chosen. It's like PRNG up to a point then it's not otherwise how can you give out 96% over 10 million spins if it's truly random.
I'm a slot tech but I don't work with PAR sheets we're purposely kept at arms length for a reason.
Timing doesn't have to be perfect - only enough to offset the house edge.
> So even if they understand how a machine’s PRNG functions, hackers would also have to analyze the machine’s gameplay to discern its pattern. That requires both time and substantial computing power
I would have guessed that the CPU requirements to process the video and map it against the PRNG characteristics would be a bit much for a smartphone, but given how powerful they are these days, that may well be flawed assumption.
Interesting how the core of an article gets explained with a few sentences given a small amount of background.