Earlier quoted context omitted.
Gathering foreign intelligence. It's not like their overarching mission is a huge secret. http://www.nsa.gov/about/mission/index.shtml
At the expense of the sanity and security of those who the foreign intelligence is meant to protect? This is an obvious abuse with extreme existential consequences. Sort of reminds of this book I read as a kid: http://en.wikipedia.org/wiki/Momo_(novel)#Plot_summary
Bruce Schneier made a couple of observations on the slide decks[2]:
24 people were able to identify "a list of 3000+ potential ORBs" in 5-8 hours. The presentation does not go on to say whether all of those computers were actually infected.
...
The slides never say how many of the "potential ORBs" CSEC discovers or the computers that register positive in GCHQ's "Orb identification" are actually infected
Despite this, the article authors have no problem tossing in assertions not made in their source material, such as: "these spy agencies try to attack every possible system they can, presumably as it might provide access to further systems. Systems may be attacked simply because they might eventually create a path towards a valuable espionage target, even without actionable information indicating this will ever be the case." or "Thus, system and network administrators now face the threat of industrial espionage, sabotage and human rights violations created by nation-state ad- versaries indiscriminately attacking network infrastructure and breaking into services." Heck, as far as I can tell they apparently threw in Slide 9-16 (what appears to generic description of network hacking) solely so that they could include the phrase "The NSA presentation makes it clear that the agency embraces the mindset of criminals." (Neglecting to mention that the supposed "tools to support this criminal process" are a Wireshark dump of an ICMP ping response [Slide 14], what looks to be an FTP session labelled "Iraqi Ministry of Finance" showing an attempt at brute forcing the administrator account [Slide 15], and a screenshot of a freshly opened cmd.exe [Slide 16])
If the average person reads through this without looking at the text critically, they're going to walk away thinking "holy crap, they're hacking everyone!", which would indeed be terrifying. The problem is that the evidence needed to reach that conclusion isn't actually there. Nothing is shown regarding any actual process for selecting hosts to use as relays, or any actual number of hosts that they hack into. One commenter on the Schneier article[3] points out that they can't just indiscriminately gain control of hosts - the host isn't necessarily going to be reliable and the chances of them getting caught increase quickly as the number of hacked hosts increases. Nor do they mention if there is any effort to assess the potential political damage that may arise from the target selection. I'd be pretty pissed if I found out that my laptop was being covertly used to hack on their behalf, but on the other end of the scale I don't care if some random open SMTP server in Nigeria is being used by the NSA to spy on North Korea.
[1] http://www.heise.de/ct/artikel/NSA-GCHQ-The-HACIENDA-Program...
[2] https://www.schneier.com/blog/archives/2014/08/nsagchqcesc_i...
[3] https://www.schneier.com/blog/archives/2014/08/nsagchqcesc_i...