I hope I don't sound like I'm sticking up for the procurement process that generated this site. The site was bought was, I'm sure, a pile of poop. I just have trouble with people's utterly unrealistic expectations of how security works in real applications. Forget Healthcare.gov; I mean real applications, ones people rely on every day.
Nothing is secure from the start. Everything has bugs.