It's probably is sutible for public facing sites, just not globablly.
Little bobby tables doesn't need the ability to dump your users or credit cards, even if he does need access to all the blog posts.
I have to read up on the feature a bit more, but it sounds a potentially massive win if you build the support into an orm / framework.