@hakan_geijer Yeah, I would say defense in depth always needs to be emphasized. We should be operating on the assumption that all our data is public (and a lot of it just is), and the admins should assume the users are posting things they shouldn't be.
Always need to be thinking along the lines of If (or when) I (or someone else) fucks up some security practice, what are the consequences and how best to mitigate them. There's no silver bullet to keeping yourself or others safe.