This paragraph interests me the most.
For one, it's clear that their goal is opportunistic decryption; that is, decrypting everything and being able to search through it, rather than targeting known endpoints. This is an important point that a lot of people miss when debating cryptography. While it's fairly likely that the government can find ways to access any communication they want in a targeted manner, as they have so many means to do so (hacking the endpoints, physically breaking in and performing an evil maid attack, etc), widespread encryption is generally good enough to prevent opportunistic data gathering.
The other point I note is that they only mention "web chats and phone calls" in their breakthrough. It doesn't sound like the breakthrough is something that works well for arbitrary SSL connections. The main link I can see between web chats and phone calls is that they are long lived connections, with bursty traffic (HTTP or email protocols, on the other hand, tend to stream a lot of data at once, and then the connection is closed). I'm wondering if there's some kind of traffic or timing analysis vulnerability that they've discovered.
Also interesting is this quote from the Guardian article:
> To help secure an insider advantage, GCHQ also established a Humint Operations Team (HOT). Humint, short for "human intelligence" refers to information gleaned directly from sources or undercover agents. > > This GCHQ team was, according to an internal document, "responsible for identifying, recruiting and running covert agents in the global telecommunications industry."
Various technology companies have been adamant in maintaining that they haven't been been giving the NSA direct access to their data. However, with HUMINT programs like this, you always have to wonder if the NSA has hired anyone within such companies to put backdoors into their systems, without authorization by the company. Obviously, they'd have to be subtle about it (it's hard to install new gigabit fiber pipes to siphon off the data without anyone noticing), but just setting up a way for the NSA to covertly run queries, disguised as some other type of job that would normally run on the system, would probably not be too hard to do.