Paste a verification link. The winners are recomputed from the seed and the list, here in your browser.
What the check does
A verification link from the wheel or the name picker contains the time of the draw, the full list in order, the winners, the seed and a fingerprint. This page ignores the recorded winners, computes them again from the seed and the list, and compares. It also recomputes the fingerprint.
The method, so you can check it without us
The calculation is short enough to reproduce in any language with SHA-256.
- The seed is 32 random bytes from
crypto.getRandomValues, written as 64 hexadecimal characters. - Block i of the random stream is the SHA-256 of the text
seed:i, with i starting at 0. Each block is read as eight 32-bit numbers, most significant byte first. - Each draw uses two numbers from the stream: the lower 21 bits of the first followed by the 32 bits of the second, a 53-bit value. If the value is not below the largest multiple of n that fits in 253, it is discarded and the next two numbers are used. The result is the value modulo n.
- For winners without repeats, start from the positions 0 to n − 1. For the k-th winner, counting from 0, draw a number below n − k, add k, and swap that position with position k. The first positions are the winners, in order. When repeats are allowed, each winner is simply one draw below n.
- The fingerprint is the SHA-256 of the JSON text
{"participants":[…],"seed":"…"}, with the list in order and no extra spaces.
Limits worth knowing
A passing check ties the winners to the seed and the list. It says nothing about how the list was put together, and it cannot show that the organiser drew once. If a draw matters, ask for it to be made live and for the verification link to be published straight away.