Potential Security Issue / Question

Upon screwing with my application, I noticed that when I am developing a page, I can select to go into debug mode. When I do, the URL changes from "f?p=&APP_ID.:&PAGE_ID.:&SESSION_ID.::::" to "f?p=&APP_ID.:&PAGE_ID.:&SESSION_ID.::YES::".
This "YES" in the URL changes the page view to a debug view, which shows hidden items, sql statements which reveal tables and columns, and anything else included in the page processing phase.
So, I logged into my application (as well as some others) on a few different PCs without logging into HTMLDB (so, therefore, I was not in development mode) and placed the "YES" in the URL.
And BAM, it revealed all the processing information. I don't really like the idea of this being a easy security target when I have a large amount of people using my application.
Is this a known problem with known solutions, and if a solution (such as turning this feature off) exists, what is it?
Any help would be fantastic,

Ah, ok. That makes sense.
So, once you set the Build Status to 'Run Application Only' the application no longer appears in the development environment, but what if you wanted this today, but in a week you decided there was additional development needed? Is there a simple way to bring it back?
I did notice that if you go into the workspace and select any application which is available in the development environment, the later portion of the url will look something like 'RP:FB_FLOW_ID,F4000_P1_FLOW,P1_FIND:333%2C333%2C', where the two instances of 333 refer to the application ID. If you remember the application ID of the application which is no longer in the development environment, you can replace the 333 with the ID. This will bring you into the Application Builder homepage for this application.

