i don't buy their security claims (weak as they are), and i don't think anyone else should either. the complexity involved in their toolchain implies a very long beta period to reveal exploits. even the existing web model is rife with security issues...and thats just for standard markup and scripting (see the recent zero-day IE exploit). downloading binaries from the web and running them directly on your computer without having public access to the source code is just not smart.