Or you could find out that the random number generator is broken now, instead of when someone does a code inspection two years later.
Strings containing cryptographic keys must be random on secret for the security model to work. If your production environment relies on cryptography to protect something it is correct behavior to shut it down on clear evidence that the keys are broken.