For greater clarity, the problem is not that you as a developer are lazy. It is that you as a developer likely spend time doing things that do not help make code secure, and things that actively make security harder, because you are part of a software development culture that continuously reinforces that certain things (high levels of abstraction, generated code, hidden functionality, pedanticness) are in fact good.