Consider that SecureRandom is really a facade around multiple providers that can plug in varying implementations. :)
Trying to write a timing attack sounds much more interesting.
SecurityManager.checkSecurityAccess(java.lang.String) is called if you try and mess with the Providers.