So now locate(1) has to grow network-handling code and suddenly becomes a security target as a result and has to deal with spoofing, malicious network services and so on, where before it was only as much a target as everything that reads the filesystem and command-line (and even *that* vulnerability surface has had a security hole or two in the past).