your assumptions about cryptographically secure pseudorandom number generators (CSPRNGs for short) are incorrect - one of the key requirements of secure random number generation is the inability to predict future state given previous state. See http://en.wikipedia.org/wiki/Cryptographically_secure_pseudo..., particularly the part about the next-bit test.
The bit about RSA aiding the NSA is spot-on though, if dual EC DRBG is in fact backdoored.