> I learned in college that most random number generators use the current timestamp to generate a pseudo-random number.
> How does this differ cryptographically from algorithms like MWC1616 and xorshift128+ in backend applications?
That question doesn’t make any sense. The current timestamp would be a seed to initialise the PRNG, which can be MWC or xorshift.
> Does it really matter which random number generator you use on a webpage?
That is application dependent. If you’re coding a roulette wheel no, if you’re coding an E2E chat yes.
> It's already considered an insecure environment anyway (that's why we have server-side validation).
That is also application dependent. The client is considered insecure from the server pov because it is entirely under user control, so the user can mess with anything. But if it is acting entirely on behalf of the user then that can be the point and by design.
In the example above, you don’t care that a user fucks up their own crypto, but you do care that the crypto holds for the average user.
Even the qualitative difference between two non-CS PRNG can make or break a project due to too small a state space or short a cycle.