Earlier quoted context omitted.
Why would they do something as ridiculous as telling you its true purpose?
They wouldn't. As I said, this is to the best of my knowledge. However, I believe I would know because it's not like one day the CEO came to us with a folder filled with requirements to be implemented. This is something that started very small ("find a way to force reboot a PC remotely if it's non-responsive") and evolved from there over months/years. I endured way too many meetings were design decisions were made. U…
That's not how the intelligence agencies operate.
> evolved from there over months/years
THIS is how they influence standards and design choices. We know that in 2013 the NSA budgeted at least $250M to programs such as "BULLRUN" that which intended to "Insert vulnerabilities into commercial encryption networks, IT systems, and endpoint communication devices..."[1].
For an example of how this works, see John Gilmore's description[2] of how the NSA influenced IPSEC. They don't use a folder of requirements; instead they gain influence over enough people to complain about "efficiency" or other distractions and occasionally add a confusing or complicated requirement that just happens to weaken security.
PHK gave an outstanding talk[3] that everyone should see about the broader subject of how the common model most people have about how the NSA works is obsolete.
[1] http://www.nytimes.com/interactive/2013/09/05/us/documents-r...
[2] https://www.mail-archive.com/cryptography@metzdowd.com/msg12...
[3] https://archive.fosdem.org/2014/schedule/event/nsa_operation...