1. Write a normal message discussing his favorite videogame on Ars Technica.
2. Encode his public key in it.
3. Use the WL public key (already available to him via the hypothetical stegano-crypto suite in common distros) to derive a shared secret.
4. Use the secret to encode and hide 20 top secret slides in his holiday family photos and upload them to his flickr account.
5. Write another post on Ars discussing some other videogame, hiding in it the URL to his flickr photos.
6. Meanwhile, WL monitors the several thousand posts per day on the most used internet forums, and detects a possible public key and tries to decrypt all the messages within the next 24 with the common secret that could be derived using it. One of them has correct checksum after decryption and gives the URL to the photos.
7. WL also daily randomly visits several thousand photos on flickr, including this time the one with the sent URL. After it gets it, it uses the shared secret and gets the message.
This whole process could be accomplished without leaving the room, without transmitting any suspicious data or contacting suspicious addresses, and would be indistinguishable from his normal online activity. As long as his computer or the WL private key are not compromised it should be perfectly untraceable.
I fail to see how arranging for a microsd card to be sent over to WL would be easier to accomplish, assuming he could be tracked and recorded constantly.
If it comes to wasting 2 MB per CD on the odd chance it could aid a whistleblower of similar importance every couple of decades, I'm all for it.