My biggest beef with "Windows Security" (if such a thing exists) is that the system and applications all have this mindset where they like to automatically find and run random programs. Regardless of the under-the-hood heritage, that kind of behaviour is just begging for infection.

For most personal systems and products, I feel that security is way overdone in general, making systems harder to use than they need to be. Most of that could go away if apps would simply stop including loopholes to automatically run code they find in attachments, documents, websites, and/or inserted media.
