Pretty accurate, although I do sense some irony in his comment given that OpenBSD continues to use C and their 'solution' to memory bugs is 'add a bunch of shit to the kernel for when it blows up.'
You mean like every other OS in production?
That’s a defeatist attitude. Why ever try to make progress on security if this is how you feel?
It’s like saying Microsoft never should have tried to make Windows more secure than it was in the XP days.
More than defeatist, its relativist. Minimizing the trusted computing base is an important tool for higher security guarantees. It's obvious that whatever the size of your TCB, a bug is a bug. In any case, i believe TDR's rant was specifically about x86 and not about virtualization or any kind of low level isolation per se.