This replaces the usage of the non-cryptographically secure math.Rand with the system CSPRNG accessed via crypto.Rand. Signed-off-by: John Sahhar <john@gravitl.com>