Such blatant security holes are why Google resorts to measures like this: https://cloudplatform.googleblog.com/2017/08/Titan-in-depth-...
The only thing that is going to change the face of the security market is that the loop between responsibility and inaction gets closed; as things stand today, the primary difficulty in the space is that for your average, not-very-knowledgeable customer, there is effectively no difference in mostly fraudulent security solutions and real ones - both get auditors out of your hair, so why bother buying anything real (or even not deploying anything like Comodo which actually makes things worse but still checks the box)?