Microsoft have never exactly had a reputation of security-conscious developments. However you do have a point: building secure software is close to impossible, and that's why we should build software that collects the smallest amount possible of personal information.
This is an excellent question/framing. The security model used in the industry right now is insane and doomed to fail, and yet it is relentlessly pushed forth and defended.