There is still a possibility, a scenario only a crazy conspiracy theorist could imagine a few years back, but I believe the current development of closed chipsets could soon allow remote penetration into any machine using any network card by any vendor, and in a way that nobody can even sniff the suspicious traffic over the network.
It seems really complicated, if not impossible, but I'm starting to think it can be done if one has full access to the chipsets and their firmware (users, admins and developers don't, vendors and their "partners" do).
Let's assume a system where every piece of hardware has a closed device driver, or part of it, CPU included. We're there, or very close. It's not that hard to imagine a system within the system that can access data (hard drives have closed blobs), read passwords before they are encrypted through keylogging (USB sniffing), make screenshots of the desktop (video card closed blobs) and send them wherever they're instructed to (network card blobs), not to mention downloading and executing arbitrary code.
Now one could object that the traffic could be easily intercepted, but what if all network chipsets of all vendors, including those inside routers, had a small set of instructions to intercept any magic packet satisfying some rules and treat it differently. Let's say send it to some hardcoded addresses without counting them or reporting them to user applications; even leds on front panels would not report those packets passing through. The only way to realize something fishy is going on would be by tapping physically into the network cable using non-network dedicated chipsets, say very fast digital analyzers, decode all traffic and match it with what a normal sniffer would report.
I admit this is a crazy scenario, but if an entity with nearly infinite resources had the power to force any hardware vendor to put spying hardware/firmware into every machine, wouldn't it attempt to do something like that?