How would you reasonably estimate the NSA's academic prowess when it comes to crypto/codebreaking? How does this compare to the state-of-the-art in academia?
I am less interested (but definitely so) in knowing or estimating more about how such a budget helps in deploying and building systems to collect/store intelligence information. I also wouldn't be surprised if they are fairly ahead of the curve in terms of zero-day exploits and the like.
The thing that most makes me curious is in terms of pure mathematics (like better factoring algorithms, better predictors of pseudorandomness, weaknesses in commonly used parameters or poor choice of certain elliptic curves, say).
There are few interesting pieces of information that would help
-- a rough headcount of people in positions comparable to post-docs and professors in the worldwide crypto/math community. I find it incredibly hard to imagine a mathematical breakthrough without significant training and continuous involvement in the research community. Do they get a fair share of the best mathematicians out there? Does the pay make it a fairly attractive destination?
-- whether or not they have an active "collaboration" and "internal publication" environment, once again, comparable to the dozen or so reputable conferences occurring yearly that allows for exchange of several interesting ideas across 100s of people with the express incentive in attending these conferences being discussion and collaboration.
-- how much we can extrapolate from just 2 instances (from what I know) of the NSA being a decade or more ahead of the curve (the DES S-box and public-key cryptosystem examples). What's a reasonable way, as outsiders, of starting to get a legitimate guess? Do we have more examples or at least hints of such possible examples?
(ps: I see after posting this that several other people have raised similar points in the thread. I'd love to learn more about why Bruce Schneier thought that the NSA was decades ahead in 1996 and whether he holds the same opinion in 2013)