Earlier quoted context omitted.
Yes, that's true. That's what the situation in the article was, a hostile WiFi access point. I'd say that running a modern platform countermeasures are only useful up to the point that you trust your OS maker and telco. So if you can get your data encrypted until it reaches a major telco's network, then you are almost as safe as if it were all encrypted.
> That's what the situation in the article was, a hostile WiFi access point. The point of the article was not the hostile AP, but to simulate a pervasive threat: we would create a pint-sized version of the Internet surveillance infrastructure used by the National Security Agency... Porcello would become our one-man equivalent of the NSA’s Special Source Operations department
The broad surveillance of any practical intelligence apparatus only bothers to do that to target actual subjects of interest, and don't have infinite leeway to not produce results while doing it - i.e. if the NSA produces no useful intelligence on Al Qaeda for a few months, they're looking at budget cuts.
Or to put it another way: how many man hours did they expend on this effort, and how many people do they actually think work for the NSA? It's certainly not "millions".