The level of code safety in smart contracts is abysmally bad today, Ethereum didn't further the state of the art with EVM/Solidity (quite the opposite), and this needs to be fixed before any serious business can rely on a DApp.
Smart contracts are like aerospace engineering, not like iStore apps development; delivering slightly buggy code, written as fast as possible, by easily interchangeable developers, doesn't cut it. It's worse than for aerospace actually: when you design a plane, your opponents are the laws of physics, which merely don't care about you. When designing a smart contract, hackers are specifically after you, and statistically, some of them are smarter than you and your code.
> 2. I locate and bribe/extort your main influencer/s
How is it different from the current practices of bribing executives and misleading shareholders (naively supposing that shareholders need to be mislead in order to pass bad, narrow-sighted judgements)?
> There are so many other fun problems with code-as-immutable-law for human institutions.
Indeed!
> It's concerning that none of these are even remotely addressed in the Colony literature
I take Colony as an experiment. As hinted above, I think you'd be a fool to bet your livelihood on some Solidity code. I don't think we're able to foresee which of those problems matter, nor the compromises which best mitigate them. Like in code optimisation, you need to measure before acting; Colony will meet those issues, will try to address them, and may or may not survive the process. Whether the lessons learned benefit Colony 2.0 or another project raised from its ashes, it's hard to say, but in the great scheme of things, it doesn't matter much.