The current bootloaders are not secure when unlocked and rooted -- there is no password protection -- so with a removable SD Card anyone can boot into your bootloader and put code on your phone, even if you have USB Debugging deactivated. Removing the SD Card is one step towards solving this.
The next step to hardening the phone would be to provide a security check to access the bootloader. One of the reasons given as to why this hasn't happened is because the keyboard interface isn't loaded in the bootloader so you can't enter a password. However, you can navigate up and down via volume keys so you could have sequence-based passwords like Konami codes in video games.
Being that inexpensive, and off-contract, is a major bonus in my mind. I have until 2014 until my Sprint contract is up. If I was able to end my contract with Sprint right now, I would. My ETF is around $175 IIRC.
I don't like that there isn't a removable battery though. That's my largest issue with the phone.
That said, I'm seldom downloading large files to my phone, and even 1 or 2 Mbps burst is usually fine for the way I use my phone.
The smartphone market in general has a lot of choice and robust competition. And the last year has taught me to worry less and just get on with it. I just bought the Nexus 7 to complement my 4S and iPad. I might just get the Nexus 4 once I get my hands on it. And the Nokia 920 looks appealing. But only one of these can be my daily driver, which is something the product reviews neglect, unfortunately.