My TLDR on this is that it all basically went haywire when MIT IS&T decided to call MIT Police for a machine downloading content on their network. They screwed up in many ways after that, but once someone unleashed a politically ambitious US Attorney on the case, it was kind of a lost cause. I don't believe universities should have police departments (or really that any private organizations should have police depart…
The "oh no, China!" thing is BS; traffic analysis would show that the china logins were (presumably) ssh portscans and not real connections. You have no evidence of that; you just made it up out of thin air. Odds would be that it was a MIT student scraping Every large network, and there's no reason to exclude MIT, gets attacked by non-students on a regular basis. They can't just assume every portscan is innocuous.
It's actually addressed in the report:
"Ultimately, MIT concluded that the communication from the IP address located in China was a — not unusual — “pinging” attempt by someone or some entity in China to determine what computer systems at MIT were available and accessible, and unrelated to the activity of this laptop."