In the majority of cases when the security folks have to talk to developers, there is a clear lack of understanding about security. The fundamental problem really boils down to the fact that a 12 year old kid in his basement has access to the exact same tools and technology the guy working on his PhD at MIT does. Let’s assume that normal people don’t care about security and don’t want to care about security, what does that mean?