(I was shocked when I just googled "exploit mitigation" and all I got back was infomercial articles by Symantec and Sophos etc. Scary. So for people browsing here and googling terms, dig deeper!)
I think we need exploit mitigation _and_ process isolation _and_ the principle of least privilege.
Fwiw, the twitter article mentions capabilities. Something I can pontificate about! I've been lucky enough to chew a _lot_ of cud with some GNOSIS/KeyKOS/caps luminaries etc. And we were still mega-fans of the Capability Object Model but _not_ believers in Capability-Based Addressing. When I did some design work with Norm Hardy on the Mill CPU I designed a temporal variant of the former that protected ... memory. OpenBSD is actually damn serious about the former. The twitter link is advocating the latter as a fix for something?
I would love to chat with anyone who wants to convince me that Capability-Based Addressing _works_ or is workable. I know that others from KeyKOS etc moved more towards the caps addressing. Anyone want to read up on some of this stuff, I warmly recommend the papers and talks for CHERI, even though I'm not a fan of caps addressing.