All in all, your post reads like a smug "Code better, noob!" while completely ignoring the tremendous extra costs that are going to be necessary to properly test hundreds of thousands of randomized builds for consistency.
So how exactly does one fit that need for privacy into the schedule and mission?
What I'd do is unplug the cameras whenever I didn't want them on. Of course I wouldn't tell them that before launch, but it only makes sense. Being several years away from a rescue team, there's no way I'd be wasting limited resources operating a camera if it wasn't necessary for the task at hand, and It's not like mission control could do anything about it. I'd be so far away that it's impossible to hold a real-time conversation, and it's designed as a one-way trip. It's not like they could fire me or punish me with anything more than a strongly worded email or nasty phone message from that distance.
Lots of folks confuse bad management with destiny. -- Frank Hubbard