when we were doing high availability, ha/cmp product we had to consider some very broad range of failure modes. misc. past posts mentioning ha/cmp
related (internet availability & "electronic commerce") post in this thread
in somewhat same period, we would do some evaluation of "security" software ... we would point out relatively trivial and easy compromises. in some cases, we were told that wasn't fair since they had never designed to handle those cases ... we have used the analogy of security vendors telling customers to install a 6' thick bank vault door in the middle of an open field (w/o mentioning the need for a vault) and to pile up all their most valuables behind the door (hoping the crooks won't notice that they don't have to attack the door, just walk around it).
only slightly off-topic ... recent post mentioning skimming, sniffing, evesdropping, data breaches (fraudulent financial transactions & PCI security standard)