root on Linux can just kill the log forwarder and erase the relevant logs, or refill them with junk.
But instead they requested that logging be disabled, thus outing themselves as acting in bad faith.
I mean, if we were to apply the equivalent from the article, then no they would not have had a reason nor been time gated.
I’ll agree that Linux security is quite limited and primitive if compared with, say, a mainframe, but it can be made less bad with a reasonable amount of effort.
The short answer would be that mainframes come with RBAC from design, unlike Unix, which has a different security model from conception and then had rbac added on top of it in some cases (such as selinux).