If he's right about the incentive for internal code sabotage, I wonder if this will strengthen the security perceptions of open source software. Particularly strongly curated open source software.
He somewhat alludes to this with his comment:
"No commercial vendors perform the level of code review that would be necessary to detect, and prove mal-intent for, this kind of sabotage."