Change (well, poorly managed change) causes instability and issues. Debian has proven that they can manage change in their distribution and it makes everyones life easier.
I've been using CentOS 5.9 on a desktop quite happily, I just compiled R from source to get a more recent version. Worth mentioning that Iceweasel (aka Firefox) was on the ESR channel so getting updates fairly regularly.
The most common case:
v1 of a package is in Debian stable. v2 comes out, is uploaded to unstable, migrates to testing. Later, v3 comes out, is uploaded to unstable, but its migration to testing is temporarily blocked because it's waiting on a major upgrade, like a new libc version, to make it into testing, which typically is done in a carefully coordinated way.
Now a security issue is found affecting all versions of the package. The upstream will (hopefully) release a patched v3, which will immediately go into unstable. The Debian security team will backport the patch to v1, and make it available to Debian stable users on security.debian.org. But testing is still distributing a vulnerable v2. There is typically no process to specifically patch v2 just for testing, because testing is staged via migrations from unstable; the usual situation is just to wait for blockage to clear and for v3 to migrate. There are occasional exceptions, mostly near releases: if it's determined that v3 won't be able to migrate before the next stable, a specially patched v2 may be uploaded to testing to get it into the next stable.
That scenario doesn't happen that often, but it's worth being aware that testing can lag behind both stable and unstable in security updates.
Sorry for the misinformation!
I just found from your link that I had no security repo configured. Just added:
deb http://security.debian.org testing/updates main
UPDATE: Here is a more correct set of settings from http://secure-testing-master.debian.net/ :
deb http://security.debian.org testing/updates main contrib non-free
deb-src http://security.debian.org testing/updates main contrib non-free
Even though they claim that contrib and non-free have no security updates, they are listed for some reason.
http://www.debian.org/vote/2013/platforms/lucas
I hope they'll tackle this security issue.