A lot of "security mindset" comes from this principle as well. In theory, you should have strong barriers everywhere, but we're not to that level of maturity yet. (I still hope to see some successful implementation of "capabilities" like in E or something before my career is over. That's an example of what I'm thinking of as maturity.) In practice you get a long way just by writing some code down, and then thinking How would I break this? Oh, hey, if I put this combination of characters into my decoding routine I'll get up to the SQL command level, oh, if I just assume that a user with no email is an admin and I let users change their email, they can become admin, etc.
It isn't theoretically ideal, but it's a lot better than not thinking this way.