If they're releasing something that they could reasonably expect the NSA to be able to crack, there's a non-zero chance other governments would be able to read it as well. That's not really "responsible disclosure" anymore.
It would be safer to just send the decryption key directly to the NSA on a CD. ;)
It would be safer to just send the decryption key directly to the NSA on a CD. ;)