I believe what he's talking about is that you do not NEED a DB for those features. One could implement authentication using a persistence mock. Eventually you will need to replace the mock with some sort of real persistence, but that is unrelated to that use case and should not affect the implementation.
I think the idea he is trying to express is that developers put too much focus on the persistence layer of an application too soon in the development. When you say I am going to use MySQL before you even write a line of code you are automatically trapping yourself and your thinking.
Persistence is meant to be an after thought of a use case; an implementation detail.