Earlier quoted context omitted.
Honestly "big companies, banks, governments" do sound like the usual suspects for writing programs insecurely to me (I work for one of those).
Yes, but if this is standard procedure in 99.999% of cases, I doubt "good enough for them" habit of running a commercial binary that's not open source (basically how the whole planet except perhaps NSA and such works), is not also good enough for some random linux user (assuning they don't trade in ultra-sensitive data).
on a side note, banks and governments often actually audit closed-source code, as they get that worked out in their contracts. Go ahead and ask Microsoft, if you could do the same...