From an expert: "often one only gets a non-cryptographic RNG by default" We should verify this is the case, and if not use an appropriate distribution.