That is a misrepresentation. You are obligated to actually put effort into securing your products, which is the only sensible stance to take.
I'm thrilled that companies are liable for crap that ends up hurting other people. I don't think they should get an easy way out, and I also like that there's a carve out for people who aren't making money off of software (like OSS devs.)