Whisper suffers from critical security flaws
xipiter.com
xipiter.com
On the other hand even major players are constantly having low hanging fruit bugs delivered to them very cheaply due to bug bounty programs (like the two recent Facebook bugs). Paying $5k a bug and having no other costs (such as bad press) could be 'cheaper' than actually giving people security training and having audits. If companies started getting burned by these failures maybe they would work harder to prevent them ahead of time.