I wonder if the recently discovered problems with non-unique key parameters could be the result of the cooperation of particular network gear vendors with NSA.
https://factorable.net/weakkeys12.conference.pdf
https://www.usenix.org/system/files/conference/usenixsecurit...