This is actually an amazing paper - well worth reading. It's like a long list of what not to do in your application (even not a security-related one).

Looks like in a couple of days running Sophos may be more dangerous than not having it installed at all...

