My first reaction when I saw him opening the chrome console was the same, its going to be a nightmare to build and maintain secure apps with this thing.
I guess the theoretical plus side, security-wise, of pushing everything through one abstraction is the potential for simplifying security. Non-layered approaches like Meteor make me a bit queasy, though. Will be interesting when its auth mechanism undergoes community security review.