Since this is a flaw any user can run into, I wouldn't get so mad about someone who doesn't know best practice running into it.
I am much more concerned that such an obvious tractable flaw exists in the first place.