I'm encountering this issue not the first time, projects that use UUID a lot have performance impact generating them sometimes having seconds to generate a UUID.
I know why this happens. This question is not about how to fix it there is plenty of information there. I'm more curious if its actually so common that it deserves to be a default...
Java defensively made it default to use SecureRandom when you generate UUID.randomUUID(), however most people use UUIDs as IDs for different things they put into a database, like a user, trade, order id, or any other entity id... but those are not sensitive in terms of security (or am i wrong?), if you are a hacker and you figured out how to guess these ids it does not give you any edge. It matters if someone generates a uuid and does MD5 over it and stores it as default password for new accounts... very rare scenario, but is obvious that it is sensitive data and true randomness is important here.
My argument here is that 99% of uses of UUID.randomUUID() do not actually care about true randomness and using secure random is not desirable behaviour for them. Do i miss something here? i'm not a hacker and i had situations where something seemed harmless but ended up being huge deal in terms of security.
So my question is : assuming that people don't use generated UUIDs on sensitive data such as private key/password generation, is it really important to have secure randomness for entity ids? what are the cases where this really matters in UUID generation?