But in fairness to NIST all of their machines have been smartcard auth only for a while now. Internal services are still under a password rotation policy, but you need a smartcard to access any NIST computer, and smartcard or RSA token for remote access to the network.
So in my opinion it could be a lot worse in terms of an actual security risk. (I am not a security researcher, just a random NIST scientist with personal opinions)
Whatever you talk about with this person can't be heard by anyone outside the room.
This room can only help guarantee that no one outside can hear you, not that the person you're talking to is trustworthy.
If the other person is a thief and you tell them where your valuables are, they could be stolen.
If the other person is trustworthy, you can be sure no one else will hear what you tell them and your secrets are safe.
The soundproof room is HTTPS. The other person is a server.
You could tell someone something like this and provide a lay person with a basic understanding of many fundamental building blocks of the web rather quickly (DNS can be explained as a phone book for example).