So, let me break it down again in concrete, proven terms suppored by decades of INFOSEC research and field work. History shows any complex system has vulnerabilities. To attack, the attacker must know the system, the vulnerability, how to exploit it, and the specific configuration. If defence in depth, then the attacker must know that for the whole route to them. So, you either have to make those have no vulnerabilities (good luck) or you have to implement measures to prevent their exploitation. That requires changing one or more of the pre-conditions of a successful attack. So, measures that eliminate vulnerabilities by design (eg Correct-by-Construction), prevent their exploitation with obfuscation/transformations, or deny enemy knowledge of their existence all provably increase security. I combine all of these in anything I do with strongest, most-analysed versions of each that are available. Positive field results followed while others get smashed repeatedly.
Note: This is especially true if the operational requirement in question, like protecting whole HW lifecycle, is in its infancy in INFOSEC techniques and has little to go on. Then, obfuscation, applying strong stuff where possible, R.E. samples (eg ChipWorks), and layers of detection/audit are best thing you can do. It's what we're doing now. You're side would suggest mask/fab/packaging companies should publish all source code and security methods online for attackers to study. Given what happened to desktops and servers, I'm glad they're listening to me instead of you. ;)
My method combines vetted mechanisms with ways that adhere to their guidelines for secure usage, is directed by tools designed by security pro's, largely invisible to users, require a hack on system to find, and force custom, difficult attacks. One can mathematically prove that my strategies possess the traits I claim along with immunity from some issues and vastly improved probabilistic security against most others. So, all the evidence is on our side in theory and the field results where compromise is rare for us even in face of pro's whose bonuses require it.
Feel free to refute this by showing me how everyone using two browsers, OpenSSL, or a desktop OS (Windows) with no changes on the same platform kept them safe from major attacks. Or led to such a high failure rate for attackers that hacks were actually worth of news rather than scaremongering. My people were safe with my methods: some systems crashed or raised exceptions while many had no problems. I'm guessing you standardize-and-open types had the same experiences? No? :P