I am "joking" in the sense that I don't expect even this 300K design to have taken that sort of vulnerability into account. I actually agree that most of it probably went into meaningless overhead. I am not joking in that I think that if you are designing a formally specified security-sensitive cyber-physical system, there are reasons why even very simple things are hard to get right.
I don't actually much care about the security of TSA hardware (my view is that it is all expensive security theater in any case). However, if you told me you spent 300K designing a very simple control interface for say, a critical component of the electrical grid, and the argument you gave me for the cost is proper security engineering, I would buy that. I certainly would prefer it to a $30 USD solution developed as a HackerRank project, even if the nominal functionality is the same.