Think of it from web development perspective. Years ago SSL were used only for financial transactions, then for e-commerce transactions. Nowadays it's considered a good practice to use it anywhere you transfer any user data or session. Isn't that our industry's equivalent of their over-classification routine? I think they basically do the same what we do with SSL - they apply their security layer to all content produced by all their users. It's exactly what we do with our security layers in software development.