I am feeling like there is a myriad of approaches:
* covert agents in companies
-- * stealing certs
-- * stealing plans
-- * planting code
* direct (yet coerced) cooperation by the corps (goog, fb, etc)
* RNG prediction based on planted flaws in various components
* direct backdoors placed in certain mfr chips (see my comment about being told cisco was required to provide backdoors as early as 1997)
---
You're correct - that we knew that this was going to be revealed. We did not know if it was going to be "NSA's quantum computer the size of a datacenter cracks all encryption in real-time" or the above multi-vector attack.
What is important to see here though is that there is, effectively, absolutely NO escape from NSA eyes.
If you encrypt, they will get you. If you refuse them, they will shut you down. If you build a whole new service to thwart them - maybe they could even lean on PayPal to freeze your funds as well /tin-foil....