I think you misunderstand him? If the crypto of a system is assumed to be correct, then that is the last place to look for a vulnerability.
Better to look at what lies on either side without relying on the pipe being vulnerable.
Better to look at what lies on either side without relying on the pipe being vulnerable.
that's how i interpreted it