To be fair, unless you are running critical infrastructure and/or processing things involving money...Linode's quality of security is adequate. (i.e. For hobbyists and small businesses that don't touch take payments but rely on ad revenue )
Security is pretty terrible everywhere in the hosting business unless you colocate your own stuff in a locked cage or pay the tier-1 vendors who cost 100% more than Linode.
How much is a locked cage really needed?
To me the risks are really someone messing with your cables and taking you off line, or accidentally pulling a power plug, which is QOS really. Not security. Can't remember when I heard of someone carting off a server or plugging in a cable to the console port (once they have gotten even into the racks and are on cameras) and doing any harm. Even if this does happen it seems fairly remote and not a concern unless you are really doing something so important that you need to lock up the servers. Sure price not being an object why not lock them up.
Also, worth noting, since most places are integrating payments through, e.g., Stripe, the requirements on the gateway server are much lower.
Among others, OP (likely) isn't referring to your own box specific security.
And the parent discussion: https://news.ycombinator.com/item?id=11136399
and they had their own massive DDOS attack which went on for days last winter (dec 2015?)