So don't have a default. Have securerandom() and insecurerandom() and make the programmer choose.
That has the advantage of avoiding problems in a generation's time: if most platforms moved to random() being secure, it would be excusable if young programmers started assuming that would be the case on older platform too.