... and quite a few of his examples rely on stealing interactive password entry, which is no kind of substitute for production line instant remote root attacks we're still seeing occasionally today.
I can't tell if this is because there isn't (or Brad couldn't think of) a more practical (which is to say, automatic) root elevation from these privileges, or if he's just being nice by ensuring that POCs inspired by his posting will do something relatively harmless.