Why India must own its dice

Every UPI payment, OTP and encrypted message rests on numbers nobody can predict — yet India imports its randomness in sealed black boxes it has never checked
Your phone buzzes. A six-digit code appears - a one-time password, or OTP. You type it in, the payment goes through, and you forget the number forever. It lived for less than a minute. And in that minute, it had only one job: to be impossible for anyone on Earth to guess. This little ritual repeats in India about nine thousand times every second. In June alone, the Unified Payments Interface (UPI) handled 22.72 billion payments - roughly 757 million a day. Every one of them begins with secret numbers that must be unpredictable. So does every Aadhaar check, every private chat, every net banking login, every defence communication. Everything starts with the same demand: give me a number nobody can guess.
The trick every computer plays
Here is the surprise: a computer cannot do this. A computer is the most obedient machine ever built. Give it the same instructions twice and it gives the same answer twice — every single time. That perfect obedience makes it hopeless at the one thing an OTP needs: genuine surprise.
So computers use a trick. They begin with one small secret number - engineers call it a “seed” — and feed it into a formula that churns out a long stream of digits. The stream looks random. It fools the eye and passes every statistical test. But it is fake randomness, like a magician’s deck of cards: it looks shuffled, yet every card sits exactly where the magician placed it. Anyone who discovers the seed can predict every “random” number that follows. And your bank’s OTP, if you trace it all the way down, always rests on one such seed.
When loaded dice break strong locks
History shows what happens when the trick goes wrong. In 1995, two students at Berkeley cracked the security of Netscape, then the world’s most popular internet browser. They never attacked the lock itself. They simply noticed that the browser built its secret numbers from the time on the clock and a few other values — things an outsider could largely guess.
In 2008, the world learnt that a single line of code, accidentally deleted from a popular operating system, had for nearly two years shrunk the possible security keys on countless servers to a pool of just a few tens of thousands. That is small enough for an attacker to try every key, one by one.
In 2012, researchers scanned the entire internet and found tens of thousands of devices using identical or related keys - because each device, switching on for the very first time, had nothing unpredictable to start from.
Notice the pattern. The mathematics never failed. The locks were flawless. The dice used to forge the keys were loaded. A lock, however strong, is only as good as the randomness behind it. And here is what should truly worry us: India’s digital systems have never faced such a public test. Not because they are perfect — but because nobody finds a problem that nobody looks for.
The universe’s only honest coin toss
So where does real randomness live? As a physicist, I find the answer beautiful.
Not in everyday life. A coin toss feels random, but it isn’t. If you knew the exact force of the flip, the spin, the air, you could predict heads or tails every time.
There is exactly one place where the future is genuinely unwritten: the quantum world — the world of atoms and light. Fire a single particle of light at a special mirror that reflects half of all light and lets the other half through. Will this one particle bounce back, or pass through? Nobody can say. Not because our instruments are weak, but because the universe itself has not decided. The answer does not exist until the moment it happens. It is the only perfectly honest coin toss in existence.
For decades, scientists wondered whether particles secretly carry hidden instructions we simply had not found. The experiments that finally ruled this out won the 2022 Nobel Prize in Physics. Einstein famously grumbled that “God does not play dice.” Eighty years on, the joke has turned around: God’s dice are now for sale. Machines that capture this quantum uncertainty are called quantum random number generators — the only randomness guaranteed by the laws of physics, rather than by the hope that nobody finds your seed.
India can make its own dice
Now come home. In 2023, India approved the National Quantum Mission with a budget of `6,003 crore. The headlines always chase one glamorous word: quantum computers. But hidden inside the mission is a quieter prize — the ability to make our own randomness. Engineers have a word for raw randomness: entropy.
The building blocks already exist. DRDO and IIT Delhi have sent quantum-protected secret keys through a hundred kilometres of optical fibre between Prayagraj and Vindhyachal. ISRO has tested quantum links through open air. C-DOT has built prototype telecom systems designed to stay secure in the quantum age. Startups in Bengaluru already sell quantum random number devices off the shelf.
What is missing is not technology. It is policy. We carefully audit who manufactures our chips and carries our data. We almost never ask who rolls our dice. The random number generators inside our payment machines, SIM cards, bank servers and defence radios are mostly imported sealed boxes — trusted mainly because opening them is inconvenient. India should treat randomness as critical infrastructure: publish national standards for it, test and certify the generators in every system that touches money, identity or defence, and use Indian quantum sources where the stakes are highest. The RBI already audits banks’ capital. CERT-In already demands reports of cyberattacks within hours. Checking the quality of the nation’s randomness is simply the next line in the same ledger. A country that stakes 757 million transactions a day on rolls of the dice should know exactly where its dice come from.
Talent in every corner
Rules, though, are only as strong as the people who carry them out. Recently, a young cybersecurity aspirant named Utsav Puri Gosai wrote to me on LinkedIn from a rural part of Gujarat. What impressed me was not just his interest, but his determination to learn despite living far from India’s big tech hubs, with far fewer opportunities.
Nature spreads its randomness perfectly evenly; India spreads opportunity far less fairly. Talent exists in every corner of this country. Visibility, mentorship and a clear path forward do not. If India is serious about cybersecurity, young people like Utsav must be able to find all three.
What quantum cannot fix
One warning: a quantum chip is not magic. Most fraud in India today breaks no code at all. It arrives as a convincing phone call, a fake “digital arrest”, a manufactured panic — and no machine, however perfect, can stop a frightened person from reading out an OTP to a stranger. Ordinary random number generators, when well designed and openly reviewed, also remain excellent; the real dangers are weak seeds, sealed black boxes and careless engineering around them. Even quantum devices can be badly built, and must be tested rather than worshipped. So the lesson of the National Quantum Mission is not “quantum everything”. It is three humbler words: Know Your Dice. So the next time your phone buzzes at a shop counter, look at those six digits for a moment before you forget them.
The author is a physicist at the University of North Carolina at Chapel Hill and a columnist on AI, infrastructure and global systems; Views presented are personal.















