@inyourbits in the sense of making secure defaults harder; my experience is:
1. a tool/system comes with secure defaults
2. a user/demo needs a set of exceptions that are contextually reasonable/acceptable
3. the tool/system grows the ability to set "policies," and declaring a custom policy implicitly overrides *all* secure defaults instead of just the ones explicitly overridden