The original tweet presenting the results in a misleading and dishonest only looks bad for the person doing it, not the project they're trying to attack.
https://twitter.com/gonzopancho/status/1110255320658558976…
The paper is also only looking at one part of the ASLR implementation rather than the whole picture.
So, aside from being a very incomplete look at ASLR, it also misses that it's only one of a set of mitigations against memory corruption attacks. Resorting to misrepresenting the results of a very obviously lacking paper to attack other projects is quite desperate and pathetic.
You quoted a statement out of context to mislead people. As I mentioned, the paper is also very lacking since it presents ASLR entropy as being the only thing of relevance to buffer overflow protection, and it also only looks at the entropy of one of several ASLR bases anyway.