Just a quick note that 'lawnchair_larry has me dead to rights on this one. I conceded awhile ago that Dual EC was a crypto backdoor (before BULLRUN and the antics that were uncovered with RSA and with the European standards, I had suggested, as some other crypto people had, that Dual EC was too hamfisted and obvious to be a crypto backdoor). But I've maintained since then that virtually nobody uses Dual EC, so its im…
While I wish I was an uber-crypto-nerd, unfortunately I only have time to be an occasional crypto geek.
EDIT: Here's a start, from another front page HN article: "Dual-EC was an NSA effort to introduce a backdoored random number generator (RNG) that, given knowledge of a secret key, allowed an attacker to observe output from the RNG and then predict its future output."