4 ms·
I'm not sure exactly what you're talking about. When the initial constants for Dual_EC_DRBG were generated, the NSA had the opportunity to generate them in such
by ReidZB 13y ago
I'm not sure exactly what you're talking about. When the initial constants for Dual_EC_DRBG were generated, the NSA had the opportunity to generate them in such a way that they would be able to predict all future outputs after observing just a few bytes of output. I don't see how this (1) doesn't qualify as a potential back door and (2) means that the NSA 'could not' insert a back door. The back door here is the knowledge of the 'secret key' that they could know (by virtue of the constant generation). Of course, it's just an alleged back door here; we don't know the truth.
By the way, the 'less-than-technically-competent journalist' here is Matthew Green, a cryptographer. So I think he's plenty technically-competent. Also, they're called elliptic curves, not 'elliptical' curves.