Earlier quoted context omitted.
Exactly, and of course this leads me to wondering about computer architectures that "require" unsafe things in their kernels, versus things like Multics where the OS and hardware co-operated at some level to make things safe. Lots of interesting questions.
One possibility might be to add hardware support for fine-grained capability security - http://www.cl.cam.ac.uk/research/security/ctsrd/
Would that help? Wouldn't the use of a safe language make hardware-level memory protection less important, not more?