I get their point, it's just ironic since modern languages very much do not suffer from "I think a password needs to be dynamically allocated".
It's also particularly silly since there are plenty of reasons why a dynamically allocated password could be quite nice.
So yeah, I get that their point is "bad devs will write unsafe code no matter what the language is", this is just a terrible case to try to make that argument.