Which should be left at zero unless you can get over the "you actually do have a responsibility to take basic safety measures for your users" hurdle.
Instead we routinely get zero security at all and also heavily encouraging people to install entirely unchecked stuff in a built-in and implicitly-trusted first party UI.