Earlier quoted context omitted.
It doesn't matter that this algorithm was backdoor-free. I'd rather see the community reject all NSA-proposed projects by default than let some of the backdoor-enabled ones sneak in once the NSA is "trusted" again. Speaking of which, is the NSA guy still running the crypto review group at the IETF? If so, how is that still a thing?! Everyone should make it clear that the NSA is not welcome in such groups anymore. Tha…
Why should the NSA receive any more scrutiny than anyone else? The NSA is in a weird position. Their mission is to secure the state and to gain advantage over adversaries. So they have a vested interest in protecting state industry from it's adversaries, and no interest in protecting anyone from themselves. So with that in mind it's perfectly reasonable for them to try to slip backdoors into anything and everything,…
They’re a large, well-funded agency with documented efforts antagonistic to the goals of cryptography. There aren’t that many organisations fitting that bill and submitting designs. It makes sense to give them special attention. Unsaid in this is what prevents the NSA from submitting a scheme through an unaffiliated researcher.