Also the author picks apart a quote, but if the assumptions in the previous paragraph is taken at face value (that an attack can have sup-10 second root with automated attacks on the logs), then even remote logging isn't a secure vector as they often aren't sent instantly so an attacker could intercept or alter them.
However I suggest that such a scenario is uncommon. Most attackers have to start outside and fight their way in which will generate plenty of logs for either external logging or FSS.
> It seems to me that systemd now also wants to play the role as some crude intrusion detection system.
FSS isn't a "intrusion detection system." It is an attempt to make logs immutable, nothing more. The nice thing about FSS is that it can be coupled with an actual IDS and the IDS can look for attempts at altering the FSS.
> If the systemd author would just have implemented sending log events to an external log server, that would have been way more useful security-wise, I think.
It isn't a binary choice. They can implement FSS and remote logging. Also it is open source so you yourself can contribute external logging.