The purpose of flipping twice is that it offsets any potential static bias (caused eg by weight difference) between the two sides.
Computers will typically combine two or more sources of entropy. In newer tls version handshakes, the entropy from both, the server and client comes into play. So there’s ways to build defense in depth.
Entropy = 7.999998 bits per byte.
If you can fit this quality on a usb, why didn’t motherboards contain a circuit like that?
Maybe they do on server boards?
How about:
f(p)=p^2/(p^2+(1-p)^2)
f(p)=2p(1-p)
f(p)=3p(1-p)
f(p)=sqrt(p)
The last two are tricky, I took them from a paper "functions arising from coin flipping" by Wastlund. (The quantum generalization is even more fun, but this text box is too small to contain it.)
A capped webcamera, CCDs pick up enough stray electrons to be reliable source of entropy.
A old cheap radio tuned to static plugged into your microphone port.
https://www.mentalfloss.com/article/81946/7-sources-randomne...
For the price GP mentioned there's a dozen vetted opensource commercial options in the bottom half of that range.
Ironically, this is the same setup as the lavalamps, but without having to pay for the lava lamps.
Testing for randomness is impossible in the YES/NO sense, so the best we have is statistical test batteries like NIST's 800-22, DieHarder and TestU01.
I own a Truerng and a Onerng, both are under $50. They performed better on Dieharder than my computer's Intel RNG. Not by a huge margin, but still. All 3 passed the minimum requirements of course.
I guess we're still well within budget.
Hardware or /dev/urandom (or Windows equivalent) and downstream library calls - many bits, high data rate