As for the specificity of the BIOS environment - he's saying you'd need to compile the BIOS code against the manufacturer's libraries AND make versions specific to board revisions. ESPECIALLY if you're doing stuff like initializing and using the soundcard (which he also addresses).
So for it to be true, this malware would be created by someone with access to several codebases and hardware docs, etc, of different motherboard manufacturers. Not to mention the test lab they must have to make sure this all works.
Not to mention the fact that in THREE YEARS none of this has been made open. OR a USB analyzer hasn't been tried, etc.
Way too many red flags here.