It's been a minute since I managed smf so *shrug*
either way with this many users, I'm sure avatars would just be an added resource hog in more ways than one.
Being fixed and being 100% secure are two different things. This forum is targeted probably like no other SMF forum out there and so has to be robust.
with smf being open source and well established I'm sure a bounty could be posted to audit and make it more secure.
[citation needed]
in case you think the dailymail is garbage here is applebaums pdf on it and other things you obviously weren't aware of.
http://cryptome.org/2013/12/appelbaum-30c3.pdf
http://www.securityartwork.es/2013/10/30/badbios-2/?lang=en
https://www.youtube.com/watch?v=C4DhFsJthgI
and just because really it isn't that new of news http://en.wikipedia.org/wiki/Van_Eck_phreaking