They vastly underestimates the "Enemy Action" risk. It won't be a DDOS attack that takes down us-east-1, it would be a Stuxnet level of direct targeting, using a combination of internal knowledge and nonlinear physical properties. And while he's right that professional hackers would have no interest in any Amazon data services (the time investment/reward is just not here), he says at the very beginning of the article a clear reason for state actors to go after it - it would cause a lot of economic damage, which is how wars are fought these days.
Not saying it has any chance of happening anytime soon, but his idea of "Enemy Action" is limited.
At any rate, it's bad business to put your eggs into one basket, and while it's less friction to use cloud formation, dynamodb, or anything that locks you into AWS - it's far better to make a system that can be deployed anywhere, at least when you start getting big enough that it matters.