Dueling over Dual_EC_DRGB: Consequences of Corrupting a Standardization Process
harvardnsj.org
harvardnsj.org
That is... immediately after they knew nine years about the backdoor. What often gets forgotten is that in the case of Dual EC the Snowden leaks only confirmed what was already known. The warnings about the possibility of a backdoor came much, much earlier (this is from 2007: https://rump2007.cr.yp.to/15-shumow.pdf ).
It has been know long before Snowden leaks that this algorithm can be backdoored, and even without that, it was considered by researchers to have some avoidable weaknesses. The approval by the NIST is also very suspicious, why use a not-so-good algorithm, with constants that come from who knows where and that may contain a backdoor.
But while there are many claims of a backdoor, there is no actual proof. It is possible that the chosen constants are honest, or even better than "nothing up my sleeve" numbers, as it has been the case for the DES S-Box. AFAIK, we don't have the key to the hypothetical backdoor, or any mathematical proof of it existence, we also don't have evidence of the backdoor being used.
Technically, Snowden didn't say anything on that matter that we didn't already know. He may have insider knowledge, but I don't remember hearing about Dual_EC_DRBG in the original leaked document.
Anyways, I see no reason to use Dual_EC_DRBG. There are doubts, and there are better alternatives.
Hope this helps.
Edit: And if you think it truly was just 1 algo then I have a bridge to sell you.