I call bullshit. Someone, somewhere long ago deep inside of the bowels of the NSA decided to deprioritize actual security, and the use of the capability security model. They knowingly did this, because actually secure computing (which they already had at the time[1,2,3]) represented a threat to the NSA , or so they thought at the time. The trade-offs seemed acceptable, because there were systemic approaches at the ti…
A. It is not metaphorically swiss-cheesed, the swiss-cheese model [1] of software security is officially endorsed. Just stack enough trash and maybe it will be okay is now accepted policy.
B. It was not driven by the NSA. It was actually driven by commercial software vendors like Microsoft and Cisco who could not meet minimum security standards, so demanded the standards be lowered to allow them to make sales. Any time the NSA gets the drivers seat in setting government security procurement standards they almost always push for actual security since the NSA is the government; they are protecting themselves. It is reasonable to distrust them for commercial and external systems, but you can trust their standards for their own and government systems are not meaningfully compromised.