I don't see any problem with discussing security issues in generalities. Especially if people want to know how secure their programs really are.

So long as we discuss it as we are without providing step by step instructions, I don't see the problem.