Earlier quoted context omitted.
When you select candidates based on whether they know how to invert a BST and other trivia it's not terribly surprisingly.
How would you select candidates to make sure they avoid this kind of security bug?
Well "we want to run an audit to find if any passwords are stored in plaintext in our file systems". Sounds like a problem any highschooler could answer?
The idea of an audit might need a person who has done a remedial level of security work.