I'm not sure how I'm wasting anyone's time by pointing out charlatans spreading misinformation. That presentation is full of inaccurate attacks on all kinds of projects and technologies ranging from memory safe languages, various mitigations including ASLR, Linux and others.
I looked at that presentation in isolation because it was tweeted by an OpenBSD developer that I follow. All I'm saying is that presented is packed full of misinformation and misleading attacks. It has very little substance and clearly little understanding of anything it covers.
Even the attempt at making an ASLR timeline is completely inaccurate and it has the usual security charlatan CVE counting nonsense. As an outsider, it's extremely clear who is in the wrong. Not mention this separate misleading attack: https://twitter.com/DanielMicay/status/1110628005477400576….
The original tweet presenting the results in a misleading and dishonest only looks bad for the person doing it, not the project they're trying to attack.
https://twitter.com/gonzopancho/status/1110255320658558976…
The paper is also only looking at one part of the ASLR implementation rather than the whole picture.
I'm not seeing a situation where both sides are engaging in underhanded mud-slinging, dishonesty and bullying. There's a distinctly different approach, especially when digging a bit deeper into it. If you want to support the bullying and charlatans in this industry that's on you.