You are, of course, correct. And - - -
There should be a way for the end user to have the only clear decryption of a message.
Having lower level people with access to sensitive decrypted messages is a recipe for trouble.
As far as the Aldrich Ames and Robert Hanssen matters, where the raw information was their legitimate domain, the normal security procedures were bypassed for these folks. If followed, they would have been stopped early on. Heads should have rolled.
(And the same with the 9-11 event. Enough was known to stop these people, but as Condi said, it didn't rise to the level etc. One wonders what information had risen to the level which was occupying their attention if that matter wasn't important enough.)
