They aren't insecure really. They're pretty secure by design but people are using them for things they were never designed for like web/mobile client auth.