You could still route around it with software if these components are indeed compromised. Random number generation has always been a hot topic and a problem for deterministic machines, but I doubt there are usable hardware exploits to crack modern encryption.
It could be viable for industrial espionage where systems are even more uniform and it is imperative to keep an eye on that topic and hold hardware developers accountable.
Plus, flawed implementations can open up side channels; this seems like an endorsement of Facebook’s implementation in that sense.
Correct. AES or something is also not proven secure, we just don't know of an efficient attack on it. Since loads of people tried with significant resources, since there is often parallel discovery (so if the NSA discovers a flaw, it's likely that someone else figures it out as well), and since an algorithm is usually weakened before a complete break is found, the security community is quite sure it's secure. But it's not proven or certain.
Quote "Claude Shannon proved, using information theory considerations, that the one-time pad has a property he termed perfect secrecy"
Unless there is some fundamental hole in our understanding of physics, including thermodynamics and quantum mechanics, HRNG are the best source.
Using cryptographic ciphers for pseudorandom functions can be catastrophic, as seeding them correctly is a problem. (You still need some entropy from outside for seeding)
Of course, using one time pads is not really practical either.