Their security model is more reasonable in my opinion: https://news.ycombinator.com/item?id=27908661
But the biggest problem is the lack of sandboxing, and UNIX permissions are way too crude to be of any use. The attacker at worst can't install a video driver, but can easily add anything to your bashrc, or read the content of your browser's cache, etc.
Turning off all three kill switches kills all sensors.
Concerning the problem with the C code, yes. But it’s the same problem as with Apple, trillion-dollar company.