Computer Random vs. True Random : See the difference in how random numbers are generated.
boallen.com
boallen.com
Chances are, the Windows version not changing is a feature, not a bug. Random number generators require a seed. The same seed always provides the same stream of pseudo-random numbers. This is useful if you're, say, debugging a simulation that depends on pseudo-random numbers.
I don't do Windows system programming, but I'll be there's a way to change the seed, and then change the stream of numbers. So, I find it more likely that the people who implemented php on Windows were using the generator incorrectly, if the intention was different number streams.
The real lesson is that applications with solid randomness requirements need to be relying on their own generators (there are lots to choose from) or an OS-supplied RNG (e.g. /dev/urandom) and not ANSI C, which is underspecified.
Conclusion: PHP is buggy on windows if it does not change the seed at every execution like it is stated in the specification (documentation actually that == specification for PHP).
I'm no PRNG expert but I think I read somewhere that those techniques wouldn't significantly improve the quality of pseudo-randomness, if at all. You can't mix 2 bad wines to get a good one.
(By conincidence, I am going to be writing a game which uses cryptographically secure algorithms to generate random numbers for a procedurally generated game world. (A Galaxy of 400 Billion Stars!)
But if you define random to mean something like "caused by unexplained or mysterious forces" or "non-deterministic", then how can anything in the universe be truly random? Even atmospheric noise is created by a sequence of deterministic events, right?
A dice roll is too (brain fires synapse, I move my hand forward and release the dice, dice interact with air in certain way, dice hit table and F=ma predicts their movements, etc...). Maybe since we don't have the facilities yet to watch a person throw some dice and predict what the outcome will be, this process is non-deterministic simply because we lack the technology to sketch it out. But with sufficient technology to scan the situation and chart the end result of the dice roll based on the initial conditions, doesn't the process become completely deterministic, and not random?
But maybe I'm just stretching the definition of random to mean something that it was never meant to mean.
Your question seems more philosophical, though I think at the quantum level things become more or less random whichever way you think about it. Furthermore, Heisenberg's uncertainty principle suggests that we'll never have sufficient technology to measure both the position and momentum of a particle, which I would say is a pre-condition to observing a deterministic process at work on the quantum scale.
"He did not want to compose another Quixote —which is easy— but the Quixote itself. Needless to say, he never contemplated a mechanical transcription of the original; he did not propose to copy it. His admirable intention was to produce a few pages which would coincide—word for word and line for line—with those of Miguel de Cervantes."
http://www.schneier.com/blog/archives/2006/06/random_number_...
On OSX, the results aren't very noticeable, probably because the underlying libs are higher quality than Windows, but mt_rand() definitely produces something comparable to his random.org image.
Not sure why rand() isn't simply replaced with mt_rand() under the hood, since improving randomness will hardly break b/c... Maybe PHP9 will have that ;)
rand() on Linux: http://www.therealnewsfeed.com/randimg.php?fn=rand
mt_rand() on Linux: http://www.therealnewsfeed.com/randimg.php?fn=mt_rand
To me, at least, these are pretty indistinguishable from the "true random" image, so it seems like the bigger issue here is the faulty rand() on Windows.
It would appear that there is some kind of flaw in the pseudo-random generator used, since once can see definite patterns in the output.