apparently. I also think the whole "security audit" is not as big of a deal as some are making of it. Other than the various Open Source solutions, what commercial solutions have undergone a similar audit? And what guarantee is it that there isn't some goatse and fail hiding in those solutions that the auditors missed?

The web browser plugins are the biggest source of goatse and fail by far. By not using them, I keep the potential attack surface…minimal.