> 1) A test to see how the journalist will react and to
> flush out more information. I.e. force him to disclose
> more information so they know what he has.
I think they already know through a post event review of MicroSoft's built in auditing logs. My understanding is that Snowden was a low level Windows admin that copied stuff that was either 1) in transit through a Microsoft Sharepoint server 2) anything he could find by roaming around the intranet. The NSA disclosed that he started grabbing documents when he was working as a contractor under Dell. They said he was aggressively exploring the limits of his network access and announced that 1) documents on their intranet would from now on be encrypted 2) that they would drastically reduce the number of system and network (as in Microsoft misuse of the term) administrators.
Plus, Wikileaks leaked an AES256 encrypted insurance file that presumably is everything that have from Snowden. Wikileaks has some of the shittiest OPSEC ever (as the Manning events showed). So, we know that they probably used openssl for the encryption and that the STK string is probably a sentence, or a few sentences, from a seminal published book about liberty/privacy. The NSA has probably already cracked the insurance file key. So, if they don't have the Manning portfolio from audit logs, they probably have it from Wikileaks.
There's an ex-NSA NWC guy that is putting out a lot of excellent information on this whole thing: 20committee
https://twitter.com/20committee