Reuters: "Undisclosed until now was that RSA received $10 million in a deal that set the NSA formula as the preferred, or default, method for number generation in the BSafe software, according to two sources familiar with the contract."
And now the response.
RSA: "Recent press coverage has asserted that RSA entered into a “secret contract” with the NSA to incorporate a known flawed random number generator into its BSAFE encryption libraries. We categorically deny this allegation."
---> Only one part of the first sentence needs to be untrue for the allegation to be deniable. RSA did not incorporate a "known flawed" RNG, because it wasn't at that time. And that's not what the alleged contract was even about, but to make default.
RSA: "We have worked with the NSA, both as a vendor and an active member of the security community. We have never kept this relationship a secret and in fact have openly publicized it."
---> Focus on relationship not being secret, but contracts may be.
RSA: "RSA, as a security company, never divulges details of customer engagements, but we also categorically state that we have never entered into any contract or engaged in any project with the intention of weakening RSA’s products, or introducing potential ‘backdoors’ into our products for anyone’s use."
---> They had not positively known the RNG is flawed.