> security has a cost associated with it, and unless there are _real_ consequences, it's a cost that most software houses ain't gon' pay.
Good to see someone say this. Software need only be good enough to do the job, and only as safe as reasonably required. Systems can be secured and audited through other means, sometimes at lower expense than guaranteeing every line of software has zero risk associated.