The MAC example is a good one. You're at the point where you're trying to protect your app against a chosen ciphertext attack (pretty far up the sophistication scale), and trying to decide the MAC mode. The text in the article makes you sound like a total idiot for not knowing what the "right" choice is and making you worry that you might not get it right.
And then you get hacked because one of your admins had a ssh key on her phone and it got stolen.
Too much security analysis is missing Big Picture issues...