An axiom of secure programming is to never trust the client. You don't really know what the client is.
Often it takes several penetrations via compromised/replaced clients to get the message through.
Just look at all the discussions about why browser-based javascript encryption is problematic.