> (1) The NYT article says NSA generated Dual_EC, but does not present evidence that it's backdoored.
So all of the following is just a coincidence then?
* Publicly-released document states that as part of a project to enable SIGINT collection, the NSA "influences policies, standards, and specification for commercial public key technologies"[1]
* NYT reports "Classified N.S.A. memos appear to confirm that the fatal weakness, discovered by two Microsoft cryptographers in 2007, was engineered by the agency"[2]
* NSA was the sole editor of Dual_EC_DRBG[3]
* Dual_EC_DRBG has a property where if you know the discrete log of one of its parameters, you can predict its future output. Since it's not explained how the parameter was derived, it's possible the parameter was chosen not randomly, but in a way to ensure its discrete log is known. (Shumow and Ferguson show how this is done[4].)
> (2) Schneier isn't a subject matter expert on elliptic curve random number generators.
It's not Schneier who raised the prospect of the backdoor - Shumow and Ferguson did. It's not like the NIST
curves where Schneier says he doesn't trust them, but can't specify how they could be backdoored. Here we know exactly
how Dual_EC_DRBG could be backdoored. Schneier doesn't need any elliptic curve expertise to postulate that it is actually backdoored,
just his intuition as a security expert (which you must respect, as you quoted him to make a point above).
> It helps here to understand the gist of the purported backdoor. Basically, a (sketch of a) way to think of the issue is, NSA's ECC CSPRNG is built around curve parameters in such a way that generating numbers with it involves a public key operation, and only the public key is in the standard. The obvious question is, "what's the private key?". Obviously, you're not happy that NSA (which until recently wasn't even the confirmed author of the construction) won't say.
No, that's not quite it. The question isn't "what's the private key?"; it's "does anyone know the private key?" If the "private key" (e in Shumow's and Ferguson's presentation) were in the spec, everyone would be able to break it. We want assurance that the only way anyone could know the "private key" is by actually solving the elliptic curve discrete log problem (which is probably only possible by generating the Q parameter yourself).
> I've already addressed the "billions of deployed device" point.
I must have missed that...
[1] http://www.theguardian.com/world/interactive/2013/sep/05/sig...
[2] http://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet...
[3] ibid
[4] http://rump2007.cr.yp.to/15-shumow.pdf