Earlier quoted context omitted.
> Why would someone backdoor their own key when they could instead just mirror the data or something? Ever thought about .. let say big commercial companies (e.g. social media platforms), using keys that are either knowingly or unknowingly tweaked? A backdoor might not be trivially simple (one of the primes being fixes), but e.g. one prime be somehow part of any collection that is smaller than the pool of truly rando…
> That's a whole different topic and not what I was pointing at. No, fundamentally it is If I'm Evil Social Media Company and I want to leak your secrets to someone (the NSA, KGB, whatever), I could 1. Send your plaintext to them (easy) 2. Send them the private key (arguably even easier - I don't have to mirror the traffic, and only my key security officers need to be aware of the fact that we are doing this) 3. Figu…
I don’t disagree with your conclusion, but we are pretty sure the NSA has engaged in these attacks before: launching and pushing to standardize a patently bad RNG with very suspicious constructs and then bribing RSA Labs $10m to make it the default in their products.
So option three isn’t just good in theory, the NSA very likely put it into practice with Dual_EC_DRBG.