You had me until the anecdote. I understand the sentiment and intent of what’s being said, but as a security professional it just paints themselves, their applications, and their user base as targets. Knowing it’s a won’t fix means it’s also easier to sell exploits if not disclosing as it’s clear he doesn’t intend to upgrade to a maintained and supported version of Python, so it should work for longer than most exploits.