They largely ignore any threat that could come from US agencies, and are very presumptuous about some of their convictions (e.g. that open source is irrelevant for security).
There is a balance to be made, given that there often isn't any ideal option, but they often get that balance assessment wrong, in my opinion.
I appreciate exposing the security weaknesses of other products, but they end up adding threats that they don't have with some of their drastic views.