Earlier quoted context omitted.
Exploiting human weakness is totally fair game. I am not an NSA policy setter. I have never directly worked for any government agency, but I have worked as a computer security auditor. If you don't account for human weakness in the threat models for your high value assets, you've already lost. While there are no silver bullets, there are auditing policies [0] and technological mechanisms [1] that attempt to prevent i…
Exactly. Exploiting the human elements of a system is often the best way into any system that is trying to be secure. It's been that way since forever. There's even an entire book on the subject by Kevin Mitnick that is very well known, "The Art of Deception: Controlling the Human Element of Security"
I suspect that it's very likely that the NSA fucked up, big-time when they designed their internal security and auditing system. With the system in the state that it must have been, would they even know if an agent from $ENEMY_COUNTRY_OF_THE_MONTH had siphoned off sensitive data, shipped it back home, and vanished into the night?
I mean, the only way we became aware of this leak was the Guardian's announcement of it. It kinda feels like the NSA became aware of the situation at about the same time that we did.