Yeah I got to this in the blog and stopped:
" I don't think that we're any safer than before. That's because finding vulnerabilities has never been the bottleneck in information security. The bottleneck isn't even verifying a vulnerability report and validating its severity, as time consuming as that is. The bottleneck isn't determining the fix, creating the patch, or publishing a new release. The bottleneck is still, as ever before, getting the goddamn packages updated. "
Dude thinks security through obscurity is valid and thinks running
sudo apt update && sudo apt upgrade -y
Is the really hard part.