Rather than focus on security bugs, let’s ask the question: Which bugs in a given project should we care about? We are at a time in software history where we have decided security bugs are more equal than other bugs. But users and testing don’t really find security bugs.