You start with critical keys that are closely held. Over time other parties express the need for access ("Okay, if you promise to be good"). Nothing bad happens (that anyone can prove...) so over time more entities are brought into the circle of trust. Eventually the dog-catcher has access to your stuff.
There's no way these keys haven't already broadly leaked (I mean, before these pictures).
The whole idea of a small set of physical keys and a large number of publically available locks is, of course, utter horse poop.
The logical extension of this "security" and "industry needs to meet law enforcement in the middle" to digital keys is terrifying. And I'm guessing it's how quite a few people think about it in the TSA and other organizations.
Forget about leaks for a second.
If a mechanical engineer can get their hands on 1,000 sample locks and keys (for instance: by simply buying them) and then imaging them, is it that difficult to reverse engineer the skeleton key system?
It requires access to one (non-master) key as well as a lock which is open-able by that key. It also requires being able to generate a modest number of new keys with a key cutter (however significantly fewer than brute forcing the entire space).
IIRC, the attack boils down to: - Start with the known non-master key - Hold all but one of the teeth constant, and try different values of that one tooth until you get a different working key. This other value must be the master key's value. - Repeat until you have the master value for each tooth.
If TSA locks work the same way as the locks described in this paper, a single lock/key seems sufficient to generate the master key.