Earlier quoted context omitted.
> it's even easier to believe commonplace unintended software defects Note the fact that this was actively exploited by the Chinese. That sort of reduces the chance of this being an accident, especially since they've done this before.
Why would Chinese intelligence (or any intelligence agency) care if the vulnerability is an accident or intentional? I imagine they prefer the former, because it reveals less about their techniques, methods, etc.
Occasionally, a proven intentional vulnerability will happen, so we want to be careful not to cry wolf other times.