Alright folks, somehow ran across this:
http://www.lullabot.com/articles/drupal-and-expressionengine-security-models
Does EE’s limited response to reported exploits constitute a security-by-obscurity mentality? As a scripting language, source code is always available and simple tracking of updates may produce reverse-engineering of version updates that include security updates, that may provide opportunity to track exploits.
Is it a good idea for EE (and maybe Code Igniter) to begin to promote an open security column vis-a-vis discovered and announced security exploits?
This is not to suggest that EE is doing anything wrong; plenty of companies currently follow very similar security models, with of course Microsoft and Apple being the most prominent among many more.
Reference:
Wikipedia
Security Through Obscurity? It’s Not All Bad
Secrecy, Security, and Obscurity