I don't know where, but it sounds fairly simple to make: cut the connector off from an old headset, and solder all of the wires in it together. One of the wires (the uninsulated one) in there is ground, the other three are signal.
Yeah, I'm not sure either. I don't see it in the official accessories store.
antsar's correct though. It's simple to make one yourself. The nice thing about the security plug is that it's small; it doesn't look like your headphones' cable snapped off. :)
If you don't trust the manufacturer who put the code into your handset, how can you trust that the security plug will always work (other than checking the internal wiring yourself)?
In the case of the baseband processor, the company that put code into it is not the company that put the phone together.
It is a complex trust situation. In this case, you can reduce the number of agents you have to trust by using the security plug. This is good for security.
The handset manufacturer could still be spying on you, but if the security plug actually works as advertised it would disable all attacks that would listen in on your mic. These attacks could be deliberate by any of the companies that have code in your handset, or it could be via an accidental weakness in any of this code that is exploited by a third party. This last kind of attack is what the linked article talks about, and a security plug would actually reduce the severity of such an attack.
It's not a perfect solution, the audio routing might be hardware with simple impedance detection of a plugged in headset, which the software could ignore and continue using the mic.
In the hypothetical in which the phone has been created to act as a bug, surely it would be easy to detect the security plug and disable the microphone for normal uses while leaving it enabled for hidden use. The security plug is only secure if the wiring means that when plugged in, software cannot access the normal mic - if software can access it, it can trick the user into thinking anything.
But that's my point - if you don't trust the people putting software into your phone, why would you trust the same people with what hardware they put in?
Your argument about not trusting anything can be applied to... anything. It's not hard to make one yourself, so if you're that worried about security, don't use a third party plug.
And if you don't, you can crack the phone open and look at (much of) the wiring yourself. This is of course a lot harder with modern multi-layer PCBs, but I'd imagine still not impossible. You can at the very least take a multimeter to the microphone pins, and test whether they are indeed shorted or not.