He's still not getting it or fully recommending it any more than most have. The funny thing is that I recently read a 150 page interview with one of founders of INFOSEC, Dr Schell, that showed his employer was the same way: ignored "COMPUSEC" as useless in favor of "COMSEC" solutions to all security problems. Schell, Karger, and Anderson's tiger teams smashed every mainframe and crypto using system put in front of th…
I agree that software bugs are a bigger concern than encrypting everything. I think the problem is that not many people are starting companies around "high assurance." How do you get people to turn their PL research into startups?
So, that's one route.