1:
Homegrown crypto is routinely problematic, but properly implemented crypto keeps the agency out; gpg ciphertexts with RSA 1024 were returned as fails. is later followed by The NSA is even more cautious than the FBI, and won’t use top exploits against clueful targets unless it really matters. Intelligence services are at least aware of the risk of losing a capability, unlike vanilla law enforcement.
Reconciling these statements is disquieting. Snowden has never seen a successful decrypted RSA-1024 intercept. But he also believes that the good stuff is kept under wraps, which is what everyone else who understands SIGINT thinks as well.
2:
We can push back a bit by blocking papers from conferences or otherwise denying academic credit where researchers prefer cash or patriotism to responsible disclosure, but that only goes so far.
Well, that, and the whole thing about how publishing papers isn't merely an exercise in making the authors feel better, but also how science works.
3:
People who can pay for a new kitchen with their first exploit sale can get very patriotic; NSA contractors have a higher standard of living than academics.
I have a problem with casual innuendo about how vulnerabilities are expensive because exploiters pay so much for them. In fact, ever-increasing dollar amounts for serious vulnerabilities is what you want to see: if there's a liquid market for vulnerabilities, the last thing you want is for serious ones to be cheap. This is highly specialized engineering work; whether Ron Paul likes it or not, it commands a high rate.
A simpler response: lots of people have made enough off vuln sales to replace kitchens without ever selling them to anyone who would exploit them.
I do have a moral problem with people who sell vulnerabilities to (a) the USG or (b) people who exploit them. I do not love the emergence of vuln markets. But I am not willing to tar everyone who earns a living doing this work as an NSA shill.
Moreover: all reverence for Snowden stipulated and set aside: nobody has ever made a claim for his expertise in vulnerability research or sales. Can we be clearer about why we're meant to carefully consider his take on it?
•:
Generally, this reads a lot like STRATFOR to me. It starts out with facts and stuff that appears verifiable/falsifiable, but it trends into a sort of geopolitical/legal LARPing exercise.