I read his comments as being "there is nothing good; here's why all of these things suck, but I grudgingly guess Keyczar works for some people". The only alternatives under discussion are cryptlib, which only has C bindings currently, and djb's new thing which uses brand new (well, four year old) ciphers that nobody other than djb really understands or knows to be secure. Given that Keyczar has some major corporate backing, and a reasonable level of community support, it seems a pretty solid choice...despite its imperfections. djb's thing might be an awesome choice...but we don't know and I'm definitely not qualified to figure it out.
Again, I'm just some guy, you know? I don't understand the nuances of security very well, but I read what I can and try to make some sense out of the kinds of answers security experts provide (which, for some reason, always seem to be qualified into being no-op statements; I guess because committing to recommending something means you can be proven wrong later when that recommendation proves insecure).
So, my reading comprehension I guess is as weak as my crypto knowledge, since I came away thinking, "Well, there's nothing good to use. But maybe Keyczar or cryptlib is better than what we're doing now; djb's might be awesome in the future. cryptlib has an annoying deployment aspect and would require me to write bindings that would probably be insecure, so Keyczar seems maybe the best of a bad lot."