@Natanox there aren't enough security experts in the world to audit even a small portion of the security sensitive code being written - not to mention that experts are human too, and can make mistakes. The focus needs to be on more secure *methods* of writing code, and tools that can detect or (preferably) prevent insecure code, including formal methods that can prove that code is secure.