https://en.wikipedia.org/wiki/Dual_EC_DRBG
It's not at all impossible to put a backdoor in a protocol which requires knowledge of a key in order to exploit. This isn't even the only example where this is thought to have occured.
If you introduce a deliberate weakness to your encryption, the overall security is reduced to the security level of that weakness.
Relying on NOBUS ("nobody but us") is hubris (see shadow brokers, snowden, etc.).
There's no reason to think it would have remained a "NOBUS" backdoor forever. Especially if it was more widely used (i.e. higher value), and/or used for longer.
>Using this logic, you would say that no encryption method is possibly secure
I mean, to an extent that a little waterboarding will beat any encryption method, yes I would say that.
But, for 99.99% of people, your data isn't worth the waterboarding. On the flipside, a backdoor to, say, all TLS communication, would be very worth waterboarding people.
I wonder what other countries do? Do their agencies trust NIST or they recommend their own and run their programs for algorithms. I am thinking of say Germany, France, Britain etc.
https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisati...
https://cyber.gouv.fr/sites/default/files/document/pqc-trans...
https://www.ncsc.gov.uk/whitepaper/next-steps-preparing-for-...
> The NCSC recommends ML-KEM-768 and ML-DSA-65 as providing appropriate levels of security and efficiency for most use cases.