20
submitted 13 hours ago* (last edited 13 hours ago) by bruh@thelemmy.club to c/programming@programming.dev

I have been trying to understand how using modulus can be dangerous and can introduce nasty but into the software.

Here is an illustration: https://gist.github.com/anon7238593-create/5719c2ac8824650abbac4592ceee9408

in the notebook we can see that we used modulus to generate another random variable range which seems correct. you try to generate few number and they looks random but are they? no. here for sake of simplicity I have choose random range of 0-255 which I then convert to 0-100 range. here the probability that 0 comes is greater than having 100 because 101 doesn't evenly divide 255. there is a remainder of 53. which means the first 53 numbers are more likely to be chosen than the rest of the numbers which we can see in the graph.

you might be wondering why? it's rather simple. there are exactly 3 numbers in 0-255 that maps to number let's say 3 ( or any number less than or equal to 53 ). while there are only 2 numbers that maps to any number greater than 53. this affects their likeliness of being chosen.

which case this is fine?

only and only when the number of elements in bigger range is evenly divisible by the number of elements in smaller range. eg, ~~0-2 ( 3 elements ) 255 % 3 = 0~~ 0-4 ( 4 elements ) 256 % 4 = 0 in this case the likeliness of an element being chosen doesn't change.

hope this was useful :)

Edit:

off by one correction. thanks to @eleijeep@piefed.social

you are viewing a single comment's thread
view the rest of the comments
[-] Derg@programming.dev 9 points 13 hours ago* (last edited 8 hours ago)

If you use something like four bytes instead of one, your error drops dramatically... If you're generating numbers from 0-100, You'd have ~50 "bad" cases (just imagine the remainder is the same) out of 4 billion instead of ~50 out of 256. Unless you're running a casino or something (and even then...) it's probably "fine enough" but of course you have to know about it!

[-] bruh@thelemmy.club 3 points 13 hours ago

that's a great observation. the difference in size of the original evenly distributed random integer space and smaller integer space is important too. if the difference is big enough the smaller random integer space will be equally likely.

Unless you’re running a casino I wonder if a good CTF could be made making use of this. eg, having a casino software and task is to exploit it to have infinite money glitch or something.

this post was submitted on 31 Aug 2026
20 points (95.5% liked)

Programming

28304 readers
413 users here now

Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!

Cross posting is strongly encouraged in the instance. If you feel your post or another person's post makes sense in another community cross post into it.

Hope you enjoy the instance!

Rules

Rules

  • Follow the programming.dev instance rules
  • Keep content related to programming in some way
  • If you're posting long videos try to add in some form of tldr for those who don't want to watch videos

Wormhole

Follow the wormhole through a path of communities !webdev@programming.dev



founded 3 years ago
MODERATORS