Python: random is unsafe for passwords and tokens; use secrets
An item from the LWN feed reminds readers that the random module is not suitable for passwords and tokens, and that the secrets module, added in Python 3.6 in 2016, is the intended choice.
According to the machine-translated LWN feed item, Python provides two modules for random values, but only one is suitable for security purposes. The random module was long used for passwords and tokens, even though its documentation said it was not appropriate for cryptography. In 2015, the core Python team debated making random secure by default, but the outcome was different: in 2016, Python 3.6 added the secrets module, intended for passwords, tokens and other sensitive values.
The text notes that misuse of random still occurs at times and that it is worth examining how each random-number module should be used. It does not include code examples, metrics or incident cases. For details, consult the original source on the LWN feed, dated 6 October 2026.