* The overwhelming majority of vendors here list Dual_EC_DRBG along with the HMAC and CTR DRBGs. A reminder: Dual_EC is a catastrophically slow CSPRNG that relies on bignum multiplication; if you pay any attention to crypto performance at all, you have every incentive never to use Dual_EC, and to an almost reasonable first approximation, nobody does. The HMAC and CTR CSPRNGs are innocuous designs based on simple conventional crypto.
* I'm a little suspicious of this list because it suggests Windows Server 2008 and Windows 7 use only Dual_EC. Neither do; you'd have to go through contortions to make Windows use Dual_EC. Obviously, the list is about certifications and not actual field configurations, but still, you should know: Windows does not rely on Dual_EC.
* Here are the products (other than Windows, which, see above) that are listed as only certifying Dual_EC:
Lancope
Mocana
McAfee Firewall Console
Thales Datacryptor
None of these are particularly important industry products. McAfee is not a leading firewall vendor (Cisco and Juniper are). Lancope is a niche intrusion detection product, and Lancope is not exactly a hotbed of cryptographic research, if you get my drift. Also, the CSPRNG Lancope would be using would be relevant only to their admin console. I don't know what Mocana or Thales do, which could be my ignorance showing, or it could be telling given what I do for a living.Here's what Bruce Schneier had to say about the Dual EC DRBG:
"If this story leaves you confused, join the club. I don't understand why the NSA was so insistent about including Dual_EC_DRBG in the standard. It makes no sense as a trap door: It's public, and rather obvious. It makes no sense from an engineering perspective: It's too slow for anyone to willingly use it. And it makes no sense from a backwards-compatibility perspective: Swapping one random-number generator for another is easy."
This is basically my take on Dual EC as well. I am not putting it past the NSA to backdoor a crypto standard (I would bet against it being a NIST standard --- if they backdoored a standard, my money is on a telephony/RF one --- but I would not bet my house against it). But this would be an inexplicable backdoor to add.