Not really. They say "dweb resolvers ideally provide.." but that is opinion. DNSSec covers #1 (with more security than trusting a 3rd party ENS resolver, actually), and #3 is also a problem for non dot-eth domains. I don't see much value in #2 personally.
That said, I found elsewhere in the cloudflare site (https://www.cloudflare.com/en-ca/distributed-web-gateway/) that they do indeed support IPFS DNSLink on their IPFS proxy, so ill shut up about it :)
I guess its more a way of them tacking on additional 3rd-party resolvers, instead of proposing to resolve IPFS via blockchain.