Sorry; I thought one of the points of the article is that some pro-active security measures (I think of them as prophylactic or preventative) are unpalatable to kernel developers, but would remove avenues for abuse by buggy user-space programs; removing symlinks in sticky directories is one example.
I understand and agree with the rejection of these kinds of patches: it's not the kernel's job to fix user-space bugs. But as an option, under debugging or something, could it at least warn, "Hey, app developer, you've left a potential security hole"?