I conceded awhile ago that Dual EC was a crypto backdoor (before BULLRUN and the antics that were uncovered with RSA and with the European standards, I had suggested, as some other crypto people had, that Dual EC was too hamfisted and obvious to be a crypto backdoor).
But I've maintained since then that virtually nobody uses Dual EC, so its impact --- while clearly malign! --- is probably limited.
Nope. ScreenOS apparently (I'm not 100% sure, but that seems to be the way the wind is blowing) uses it to key VPN connections!
FULLY CONCEDED. The immediate known practical impact of Dual EC is, if that's true, enormous.
The weird thing about this particular backdoor is that the adversary seems to have modified the Dual EC parameters. Dual EC is an RNG with an embedded public key, where an adversary with the private key can "decrypt" the random bytes it generates to recover its state and rewind/fast forward it. This backdoor appears to swap out the public key, which is something NSA has no interest in doing.
My money is that this is the work of GCHQ, the world's most unhinged signals intelligence agency, and our partners in peace.