Lol, you just used SE and security in the same sentence.
I take it you weren't around for the mass hackings prior to the introduction of token-IDs?
edit: And the complete and utter fail (on SE's behalf) that was the hacking of FList plus that got a couple of accounts stripped/sent to another server.