[0] https://groups.google.com/d/msg/django-developers/YwlZ9m9k1b...
[1] https://github.com/django/django/commit/b0ce6fe656873825271b...
https://github.com/getsentry/sentry/blob/ea8fe10d117f5325f9e...
And if the secret key were secure, the pickle use would not be vulnerable.
Still, multiple layers of security, yadda yadda, sure.
But this is beyond the pickle issue. I'm not sure I'm completely convinced you should not use pickle for browser cookies that are appropriately cryptographically verified. (although fwiw I believe Rails changed it's default cookie serialization to use json instead of the ruby equivalent to pickle which suffered from the same issues).
(but yes you still need to implement a safe unserialize white list)
2. There are many situations where the person who we want to see the stack trace and debug output does not have access to the console output. E.g. hosting the service internally for a QA team.
In general, it is an error often made by people who focus on security to think that security considerations always trump convenience. In fact, it is a trade off like any other.