Skip to content
Rota Nacional

Cyber ·

Python: random is unsafe for passwords and tokens; use secrets

An item from the LWN feed reminds readers that the random module is not suitable for passwords and tokens, and that the secrets module, added in Python 3.6 in 2016, is the intended choice.

According to the machine-translated LWN feed item, Python provides two modules for random values, but only one is suitable for security purposes. The random module was long used for passwords and tokens, even though its documentation said it was not appropriate for cryptography. In 2015, the core Python team debated making random secure by default, but the outcome was different: in 2016, Python 3.6 added the secrets module, intended for passwords, tokens and other sensitive values.

The text notes that misuse of random still occurs at times and that it is worth examining how each random-number module should be used. It does not include code examples, metrics or incident cases. For details, consult the original source on the LWN feed, dated 6 October 2026.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free