Earlier quoted context omitted.
In principle, that's what the NSA would be doing. When DES was developed and standardized in 1976, the NSA had input in selecting some of the constants that were chosen for it [0]. It wasn't until the late 80s when independent development of differential cryptanalysis [1] came out, and people realized that the DES constants were deliberately chosen to be resistant to this attack. The NSA has since turned away from th…
Or maybe the choice of Dual EC DRBG constants are intended to protect against a new cryptanalysis technique known only to the NSA
https://en.m.wikipedia.org/wiki/Bullrun_(decryption_program)
stop simping for the nsa