IIS still defaults to adding 'served by ASP.Net' as a 'x-powered-by'. Something I again often forget to remove. And certain versions of MVC you have to jump through hoops to remove their x-aspnetmvc-version. And on top of that you can often tell by just looking at which js files have been included. Is it using MS js files? Yes, then it's 99% IIS with ASP.Net.
So that's not what I, or I would think any reasonable developer, would considered even a vague security concern as an experienced developer with exposure to a few different frameworks can often tell the platform, and thus the probable server, by just looking at the HTML.
If it were a serious security concern MS would have patched the header by now! Instead they've added even more with MVC.
So are there any other reasons? Or is Troy just wrong in this instance?