I do not mean to say that it was justified in this particular case. I was responding to the idea that all products must be secure, even for users who do not want to pay for the added security. Also, it is not so much that I think a service should offer a discount for handling your data insecurely (although in this particular case, the insecure handling is actually cheaper on a per user basis). Rather, there is a place in the market for products that are not secure, and therefore do not have to pay to develop and maintain the security aspects of the service.
Comments
I do not mean to say that it was justified in this particular case. I was responding to the idea that all products must be secure, even for users who do not want to pay for the added security. Also, it is not so much that I think a service should offer a discount for handling your data insecurely (although in this particular case, the insecure handling is actually cheaper on a per user basis). Rather, there is a place in the market for products that are not secure, and therefore do not have to pay to develop and maintain the security aspects of the service.