Basically, Juniper used Dual_EC, which they knew was backdoored. Because they knew it was backdoored, they replaced the NSA key with their own, which they thought made it "safe."
Now it turns out that a third actor might have somehow replaced the Juniper key with their own key.
The point is that by using a CSPRNG with a backdoor, even when they tried to close that backdoor, they still left a backdoor open. Dual_EC is relevant because if the USG had never promoted it there never would have been a backdoor to leave open. Another CSPRNG would have been harder to leave insecure.
> If this back door only works by assuming Dual EC is backdoored, is that not incontrovertible proof that the NSA is behind the entire thing, which there is at least some doubt that they are?
Not necessarily. As Juniper is supposedly not using the NSA codepoints, it could have been "any" actor which changed the back door, including but not only the NSA.
Personally, I don't think it is the NSA in this case. If it were, I don't think we'd be reading about it on CNN at all.
[1] https://www.imperialviolet.org/2015/12/19/juniper.html
[2] https://kb.juniper.net/InfoCenter/index?page=content&id=KB28...