The solution
Every time you log in to a website you are assigned a unique identifier that should be random: if hackers can predict it, they can impersonate you. Computers, relying on human-coded patterns, cannot generate true randomness — which is why Cloudflare's San Francisco lobby houses a wall of 100 lava lamps, invented by British tinkerer Edward Craven Walker, filmed around the clock.
Head of cryptography Nick Sullivan explains that anything the camera captures gets incorporated into the randomness used to help create cryptographic keys — including visitors milling about and light streaming through the windows, since even subtle heat changes affect how the glistening globules undulate.
Cloudflare also planned for the obvious counterattack: a bad guy sneaking a camera into the lobby to record the same scene. The company films the movements of a pendulum in its London office and records measurements from a Geiger counter in Singapore, adding more chaos to the equation.
Why it worked
It solves a real cryptographic weakness — predictable pseudo-randomness — with a physical entropy source that is cheap, visual and almost impossible to model.
The threat model is handled explicitly: capturing one feed is not enough, because three independent physical sources on three continents feed the pool.
The mechanism has been running in production protecting wide swaths of internet traffic, not as a demo.
It is a rare security measure that visitors can literally watch working in the lobby.
What can be applied
When your system needs what computers are worst at — genuine unpredictability — borrow a physical process that even a determined adversary cannot model cheaply.
Aftermath
WIRED's 2018 visit found the system running as described, with Sullivan confirming the camera feed, the London pendulum and the Singapore Geiger counter all feeding Cloudflare's randomness pool.
FOLLOW THE EVIDENCE