Discrete mathematics · final presentation

Collisions aren't bugs.
They're arithmetic.

Simulating 100,000 bank account registrations inside a 100 millisecond window, and measuring the resulting ID collisions against what the Pigeonhole Principle and the Birthday Paradox say must happen. No amount of better code changes the answer.

1. The Pigeonhole Principle

Guaranteed, not probable

If you have N pigeons and M holes and N > M, at least one hole holds more than one pigeon.
ParameterValueWhat it is
N100,000registration requests
M~100distinct milliseconds in the window
N − M99,900collisions that must occur

Minimum collisions = N − M = 100,000 − 100 = 99,900

2. The Birthday Paradox

The 50% point arrives far earlier than intuition allows

P(collision) ≈ 1 − e^(−n² / 2M)   for M = 900,000

RegistrationsP(at least one collision)Intuition
1000.55%seems safe
50012.9%getting risky
1,00042.6%very likely
1,17850.0%the coin flip
5,00099.99%essentially certain
100,000100.0%guaranteed

With 900,000 available numbers, intuition says 1,178 users is nothing. The maths disagrees.

3. Measured against theory

SHA-256 tracks the prediction to within a tenth of a percent

Input sizeNaive mapperHash mapperTheoretical
1,000~90%0.05%0.06%
5,000~95%1.4%1.4%
10,000~97%5.4%5.4%
25,000~98%29%29%
50,000~99%63%63%
100,000~99%+89%89%

The cryptographic hash is enormously better than the naive scheme and still fails at scale — because the output space, not the hash quality, is the binding constraint.

4. The plots

Generated by the simulation, not drawn by hand

Collision rate comparison
01 — naive vs hash collision rate
Collision table
02 — measured against theoretical
Birthday paradox curve
03 — the birthday curve
Pigeonhole distribution
04 — pigeonhole distribution