Bullrun: NSA Crypto-Undermining and the Dual_EC_DRBG Backdoor (Revealed Sept 2013)
Introduction
In September 2013, ProPublica, the New York Times, and the Guardian jointly published an investigation drawing on Snowden documents that described a classified NSA programme codenamed Bullrun. Bullrun was described in NSA budget documents as a multi-decade effort to covertly undermine the encryption technologies used to secure internet communications — not by breaking mathematics, but by introducing weaknesses into standards, products, and implementations before they reached users.
Bullrun was the NSA counterpart to GCHQ's parallel programme, codenamed Edgehill. Together the programmes represented systematic covert action to subvert the cryptographic infrastructure on which secure internet communications depend.
What Bullrun Targeted
NSA budget documents described Bullrun as targeting the encryption used in HTTPS (the secure web), virtual private networks (VPNs), and the encryption built into fourth-generation mobile telecommunications standards. The documents described the NSA as having, by 2013, inserted ''vulnerabilities into commercial encryption systems, IT systems, networks, and endpoint communications devices used by targets.''
The methods described included: covertly influencing the development of international encryption standards through the standards bodies that set them; working with technology companies under legally compelled or voluntary arrangements to build exploitable weaknesses into their products; and developing or acquiring technical capabilities to exploit those weaknesses.
The Dual_EC_DRBG Backdoor
The most specific and technically documented component of the Bullrun revelations concerned a random number generator standard called Dual Elliptic Curve Deterministic Random Bit Generator (Dual_EC_DRBG). The National Institute of Standards and Technology (NIST) had standardised Dual_EC_DRBG in Special Publication 800-90A in 2006.
Cryptographers had noted anomalies in Dual_EC_DRBG as early as 2006 and 2007. Researchers at Microsoft Research, including Dan Shumow and Niels Ferguson, demonstrated at the CRYPTO 2007 conference that the standard contained a potential backdoor: if the constants used in the elliptic curve algorithm were chosen in a specific way — knowing a secret discrete logarithm relationship between them — an observer who knew that relationship could predict the output of the generator from a small sample of its output, breaking the randomness on which cryptographic security depends.
The Snowden documents, as reported by the joint investigation, indicated that the NSA had worked to have Dual_EC_DRBG standardised by NIST and had pushed for its adoption, with knowledge of the backdoor. NIST subsequently reopened the standard for public comment and in 2014 withdrew Dual_EC_DRBG from its guidelines.
The RSA $10 Million Contract
In December 2013, Reuters reported that RSA Security — at the time one of the most prominent cryptography companies in the world, maker of the widely-used SecurID authentication token and the BSAFE encryption toolkit — had entered into a $10 million contract with the NSA in 2004. Under the contract, RSA made Dual_EC_DRBG the default random number generator in BSAFE. The result was that products built on BSAFE — widely used in commercial and government applications — were potentially vulnerable to anyone possessing the backdoor key.
RSA denied that it had knowingly incorporated a backdoor. The company stated it had not known at the time that Dual_EC_DRBG was potentially compromised. The plausibility of this denial was contested by cryptographers who noted that the 2007 public research raising backdoor concerns was available before many BSAFE deployments.
Broader Implications
Bullrun represented a fundamental tension in national security cryptography policy: the NSA simultaneously serves as the primary US signals intelligence agency (which benefits from weakened encryption it can exploit) and as an advisor to NIST on cryptographic standards for the protection of US government and commercial systems. The Dual_EC_DRBG episode demonstrated how these roles could conflict, and how the intelligence mission could actively undermine the security mission.
The Bullrun and Dual_EC_DRBG disclosures produced lasting changes in the cryptography standards community. NIST strengthened its processes for public review of standards, and the episode accelerated efforts across the industry to move away from algorithm families where NSA involvement in standardisation was significant.
Verdict
Confirmed. Bullrun is confirmed by NSA budget documents published in the joint ProPublica/NYT/Guardian investigation, subsequent government acknowledgements, the technical analysis of Dual_EC_DRBG by independent cryptographers, NIST's withdrawal of the standard in 2014, and the Reuters reporting on the RSA $10 million contract. The programme systematically undermined commercial encryption through standards manipulation and industry cooperation.
The Sigint Enabling Project: Bullrun's Budget Line
The September 2013 joint investigation did not rest solely on prose descriptions of Bullrun's goals — it drew directly on a classified US intelligence budget document, the 2013 'black budget,' which itemised a separate but closely related NSA programme called the Sigint Enabling Project. According to the Guardian's reporting on that budget, the Sigint Enabling Project cost $254.9 million in the 2013 fiscal year alone — more than ten times the budget of the better-known PRISM collection programme — and the document stated that the project "actively engages the US and foreign IT industries to covertly influence and/or overtly leverage their commercial products' designs" to make them exploitable. The same reporting noted that since 2011 total spending on Sigint-enabling work had passed $800 million, and that the fund had been used, among other things, to work with chip manufacturers to build weaknesses into the hardware encryption chips used to secure business and government systems.
This budget line matters because it moves Bullrun from a single anecdote (Dual_EC_DRBG at RSA) to a documented, sustained institutional programme with its own multi-year funding stream, spanning software, hardware, and standards work simultaneously. Bruce Schneier, one of a small number of journalists and cryptographers given direct access to the Snowden material by the Guardian, summarised the pattern in his own September 2013 essay: the NSA's approach, he wrote, was to ask companies to "subtly change their products in undetectable ways: making the random number generator less random, leaking the key somehow, adding a common exponent to a public-key exchange protocol." Schneier pointed to earlier documented precedents — the Crypto AG affair and a suspected Lotus Notes weakening — as evidence this was a long-running institutional habit rather than a one-off Dual_EC episode, and observed that any backdoor caught in the act would typically be "explained away as a mistake," giving the agency built-in deniability.
From Standard to Real-World Exploit: The Juniper ScreenOS Incident
The clearest demonstration that a Dual_EC-style backdoor was not merely theoretical came two years after the Snowden revelations, from a company with no connection to RSA. In December 2015, Juniper Networks — a major maker of enterprise firewalls and VPN appliances — announced that an internal code review had turned up "unauthorized code" embedded in ScreenOS, the operating system running on its NetScreen firewall line. The US Department of Homeland Security's CISA issued an out-of-band alert on the disclosure, and Juniper's own SVP and CIO, Bob Worrall, stated on the company's support forum that the code "could allow a knowledgeable attacker to gain administrative access to NetScreen devices and to decrypt VPN connections."
Two distinct backdoors were involved. The first was a hardcoded authentication password hidden inside a debug string, which let anyone with a valid username bypass SSH or Telnet authentication entirely; security firm Fox-IT reportedly found the working password within about six hours of starting to look, and estimated it had been inserted into ScreenOS builds released in late 2013. Independent estimates at the time suggested roughly 26,000 NetScreen devices had SSH management exposed directly to the internet, meaning the flaw was not confined to a lab scenario.
The second backdoor was the one with a direct line back to Bullrun: it involved Dual_EC_DRBG, the same random-number-generator standard at the centre of the RSA/BSAFE story. Juniper had used Dual_EC in ScreenOS but — according to the company — had tried to protect itself by not using NSA's default elliptic-curve constant, generating its own "Q" parameter instead, and by additionally re-processing the generator's raw output through a second, faster algorithm (ANSI X9.17) before it was used, a design meant to blunt exactly the kind of prediction attack Dual_EC is vulnerable to.
How a Government Backdoor Became Somebody Else's Backdoor
That design turned out to fail on two separate fronts, and the way it failed is itself part of the Bullrun story. First, cryptographer Matthew Green's technical analysis, published within days of Juniper's disclosure, found a coding flaw in the ScreenOS implementation: a global variable governing output length was not being reset correctly, so instead of passing Dual_EC's output through the safer secondary algorithm, the code sometimes emitted 32 bytes of raw Dual_EC output directly — precisely the material an attacker who knows the discrete-log relationship between Dual_EC's constants needs to predict all future outputs and recover a VPN session's keys. Green wrote that with this flaw in place, an attacker "can predict future outputs of the RNG after seeing a mere 30 bytes of raw output."
Second, and more striking: forensic analysis (later formalised in the peer-reviewed paper "A Systematic Analysis of the Juniper Dual EC Incident" by Checkoway, Green, and other co-authors, presented at the 2016 ACM Conference on Computer and Communications Security) found that Juniper's own self-generated Q constant had itself been silently replaced in 2012 with a different value, one whose origin nobody outside the intruder has ever identified. Because Juniper had already built a system that trusted whatever Q value sat in that memory location — precisely the architecture the NSA had originally engineered into the Dual_EC standard — swapping in a new constant was enough on its own to hand a new, unknown party the same predictive power over ScreenOS's encryption that Dual_EC was designed to give its original author. As Green put it, the intruder "made no major code changes to the encryption mechanism — they only changed parameters," which is exactly what a backdoor built on a swappable secret constant allows anyone who can reach it to do.
Juniper has never publicly confirmed who altered the constant, and no government has claimed responsibility. The episode is widely cited in the security research community not as proof of who exploited Bullrun-style tooling, but as proof that a backdoor engineered for one actor's exclusive use does not stay exclusive: once the mechanism exists in shipping code, it is available to whoever can access and modify that code, whether that is the original designer, a rival intelligence service, or a criminal group.
The Academic Case: Why Dual_EC's Flaws Were Visible All Along
A further piece of the record, less widely reported than the Snowden leaks but directly relevant to the "was this really deliberate" question, is the 2015 paper "Dual EC: A Standardized Back Door" by cryptographers Daniel J. Bernstein, Tanja Lange, and Ruben Niederhagen. Their analysis, made public on the Cryptology ePrint Archive, walked through the standard's history and argued that Dual_EC carried design properties that made no sense on ordinary engineering grounds: the authors note the algorithm was "much slower than the alternatives and the numbers it provides are more biased, i.e., not random" compared to competing NIST-approved generators available at the same time. In ordinary cryptographic engineering, an algorithm that is both slower and statistically worse than its rivals is not normally adopted, let alone standardised by three separate bodies (NIST, ANSI, and ISO) and then defended for years after independent researchers flagged the backdoor risk in 2007. Bernstein, Lange, and Niederhagen's paper traces how the standardisation and patent process around Dual_EC allowed the anomaly to persist essentially unchallenged inside the standards ecosystem, reinforcing the 2013 reporting that this was long-run institutional strategy rather than an isolated engineering lapse.
Unresolved Questions and the Limits of the Evidence
None of this closes every gap. The precise scale of real-world NSA decryption enabled specifically through Dual_EC-based products remains classified and is not established by the public record — the Snowden documents describe capability and intent, and the RSA contract shows a commercial pathway existed, but the volume of live intelligence actually collected via Dual_EC-equipped products has never been disclosed or independently measured. Attribution for the 2012 tampering with Juniper's Q constant is likewise unresolved: it is consistent with a nation-state actor repurposing a known weakness, but ScreenOS's design meant that determining who made the change from the code alone was not possible, and Juniper's own investigation did not name a suspect. These gaps do not weaken the confirmed elements of Bullrun — the programme's existence, its budget, and the Dual_EC/RSA mechanism are documented — but they are a reminder that "confirmed programme" and "fully measured real-world impact" are different claims, and the public evidence base is strongest on the former.
Evidence Filters22
NSA budget documents confirm Bullrun programme and its objectives
SupportingStrongNSA budget documents published in the ProPublica/NYT/Guardian joint investigation describe Bullrun as a programme to covertly insert vulnerabilities into commercial encryption systems and influence international standards. The documents are primary-source confirmation.
Dual_EC_DRBG backdoor identified independently by cryptographers in 2007
SupportingStrongDan Shumow and Niels Ferguson presented research at CRYPTO 2007 demonstrating that Dual_EC_DRBG contained a potential backdoor if the elliptic curve constants were chosen with knowledge of a secret discrete logarithm. This independent cryptographic finding predates the Snowden revelations and corroborates the NSA's role.
NIST withdrew Dual_EC_DRBG from guidelines in 2014
SupportingStrongFollowing the Bullrun revelations and cryptographic analysis, NIST withdrew Dual_EC_DRBG from Special Publication 800-90A in 2014. The withdrawal of an official US government standard is a significant institutional acknowledgement of the backdoor concern.
Reuters: RSA received $10 million from NSA to default Dual_EC in BSAFE
SupportingStrongA December 2013 Reuters investigation reported that RSA Security had received a $10 million NSA contract in 2004 to make Dual_EC_DRBG the default random number generator in its BSAFE encryption toolkit, spreading the potentially backdoored generator across commercial and government applications.
RSA denied knowing Dual_EC was compromised
DebunkingRSA Security denied that it had knowingly included a backdoored generator in BSAFE, stating it had not been aware of the potential compromise at the time of the contract. The denial raises questions about due diligence given the 2007 public cryptographic research.
Rebuttal
RSA's denial concerns its own knowledge and intent, not the existence of the backdoor or the NSA contract. Independent analysis of the Dual_EC_DRBG constants confirms the mathematical basis for the backdoor regardless of what RSA knew.
Programme represented systematic conflict between NSA's intelligence and security missions
SupportingStrongBullrun highlighted a fundamental institutional tension: the NSA simultaneously advises NIST on cryptographic standards for US government and commercial security while also exploiting weaknesses in those standards for intelligence collection. The conflict of interest is structural and confirmed.
GCHQ Edgehill programme was British parallel to Bullrun
SupportingDocuments in the Snowden archive confirmed that GCHQ operated a parallel programme codenamed Edgehill with similar objectives to Bullrun, confirming the systematic Five Eyes approach to undermining commercial encryption rather than an isolated NSA activity.
Bullrun disclosures accelerated industry movement to verified cryptographic standards
SupportingFollowing the Bullrun revelations, the cryptography and internet standards communities accelerated review of NIST standards with NSA involvement, moved toward algorithm families less susceptible to NSA influence, and strengthened processes for public scrutiny of proposed standards.
Dual EC DRBG Backdoor Mathematically Confirmed
SupportingStrongCryptographers at Microsoft Research (Bernstein, Lange, et al.) published a 2013 paper demonstrating that the Dual Elliptic Curve Deterministic Random Bit Generator contained a verifiable mathematical backdoor: knowledge of the discrete logarithm relationship between two constants would allow complete prediction of outputs. NIST withdrew the algorithm from its Special Publication 800-90A in April 2014 after NSA involvement in setting the constants was established by the Snowden documents.
RSA Security Received $10 Million NSA Contract to Use Dual EC
SupportingStrongReuters reported in December 2013, citing Snowden documents, that RSA Security had accepted a $10 million NSA contract to set Dual EC DRBG as the default random number generator in its BSAFE toolkit. RSA disputed characterization of the arrangement as a secret deal, stating it had relied on NIST's 2006 standardization and the NSA's role as a trusted standards body.
Show 12 more evidence points
Scope of BULLRUN Remains Classified; Full Impact Unverified
NeutralThe published Snowden documents described BULLRUN in general terms as a program to defeat commercial encryption through multiple methods including insertion of vulnerabilities, exploitation of implementation flaws, and court orders. The full extent of the program — how many standards were compromised, which commercial products were affected — remains classified. Independent security researchers have not been able to confirm NSA access to all systems the program reportedly targeted.
Cryptographers Flagged Dual_EC_DRBG Weaknesses in 2007, Before Snowden
DebunkingDan Shumow and Niels Ferguson publicly demonstrated the potential backdoor structure of Dual_EC_DRBG at CRYPTO 2007, six years before the Snowden disclosures. Bruce Schneier and Daniel Bernstein independently noted the anomaly. This means the cryptographic community's self-correcting mechanisms partially worked: the flaw was identified, debated, and Dual_EC was rarely deployed in practice outside RSA Security's BSAFE library. The BULLRUN revelations confirmed what the research community already suspected about that specific algorithm. This limits the claim that NSA systematically subverted crypto standards undetected — at least in this case, the subversion was noticed and flagged by independent researchers operating through normal channels.
Post-Snowden Standards Processes Explicitly Excluded NSA Influence
DebunkingFollowing the 2013 Snowden disclosures, NIST withdrew Dual_EC_DRBG from its recommendations and restructured its cryptographic standards process to increase transparency and external review. The NIST Post-Quantum Cryptography competition (launched 2016) was explicitly designed with open international participation, public comment periods, and cryptanalysis rounds to prevent the kind of opaque insertion alleged with Dual_EC. Widely deployed modern standards — AES-GCM, ChaCha20-Poly1305, X25519 — have been extensively reviewed and show no credible evidence of NSA backdooring. The BULLRUN story, accurately read, is about one specific algorithm and some commercial product influence, not wholesale subversion of all encryption standards.
Juniper Networks ScreenOS firewalls found running unauthorized Dual_EC-linked backdoor code (Dec 2015)
SupportingStrongJuniper Networks disclosed that an internal code review found unauthorized code in ScreenOS enabling both administrative-access bypass and passive VPN traffic decryption. CISA issued an out-of-band alert; the VPN-decryption flaw exploited the same Dual_EC_DRBG design weakness at the heart of the RSA/BSAFE Bullrun story, demonstrating the backdoor mechanism was exploitable in a real deployed product, not just a lab construct.
Cryptographers Publicly Flagged Dual_EC Weakness in 2007, Six Years Before Snowden
DebunkingDan Shumow and Niels Ferguson presented a public analysis at CRYPTO 2007 demonstrating that Dual Elliptic Curve Deterministic Random Bit Generator had a potential backdoor structure if its constants were chosen with knowledge of a discrete logarithm relationship. This was not a secret finding — it was published in conference proceedings and widely discussed in the cryptographic community. The NSA's alleged deliberate insertion of the weakness was exposed through open academic cryptanalysis, not whistleblowing. This demonstrates that the cryptographic peer-review system eventually identified the problem through normal scientific channels.
Unknown party silently replaced Juniper's self-generated Dual_EC constant in 2012, enabling passive VPN decryption
SupportingStrongCryptographer Matthew Green's analysis and the subsequent peer-reviewed study (Checkoway et al., ACM CCS 2016) found that Juniper's own Dual_EC 'Q' parameter — intended to avoid NSA's default constant — was swapped for an unknown value in 2012 without any other code changes, letting whoever made the swap predict VPN session keys from a small sample of output. This shows a Dual_EC-style backdoor can be silently repurposed by any party able to modify the constant, not only its original designer.
Rebuttal
Attribution for the 2012 change was never established. It is consistent with a nation-state actor exploiting the built-in weakness, but neither Juniper's investigation nor independent researchers identified who made the change, so it cannot be presented as proof of a specific actor's involvement.
NSA's classified 'Sigint Enabling Project' budget documents show sustained, dedicated funding for undermining commercial crypto
SupportingStrongThe 2013 US intelligence 'black budget,' reported by the Guardian, itemised a Sigint Enabling Project costing $254.9 million in FY2013 alone (over ten times PRISM's budget), explicitly tasked with covertly influencing commercial IT product design to make it exploitable, with total Sigint-enabling spending exceeding $800 million since 2011 — establishing Bullrun as an institutionally funded, multi-year effort rather than an isolated Dual_EC incident.
Post-Snowden NIST Standards Processes Explicitly Excluded NSA Influence
DebunkingFollowing the 2013 Snowden revelations, NIST conducted an internal review, withdrew Dual_EC_DRBG from its standards, and restructured its cryptographic standards process to include external cryptographic experts and increase transparency of deliberations. NIST's post-2015 post-quantum cryptography standardization process explicitly used open international competition with public analysis periods. These institutional reforms directly addressed the vulnerability that BULLRUN revealed. Not all encryption standards are compromised; the post-2013 standards landscape reflects a measurable response to demonstrated NSA overreach.
Cryptographers Flagged Dual_EC Weakness Before Snowden
NeutralStrongDan Shumow and Niels Ferguson publicly presented mathematical analysis at CRYPTO 2007 demonstrating that Dual_EC_DRBG's parameters could contain a backdoor if generated by a party who knew the discrete-log relationship. This was six years before Snowden's disclosures. The cryptographic community's self-correcting peer review — not whistleblowing — identified the specific weakness, suggesting the NSA's influence on NIST was exploitable but not impenetrable to scrutiny. NIST withdrew Dual_EC in 2014 following the Snowden context but acting on pre-existing mathematical objections.
Academic cryptanalysis identified Dual_EC's design as statistically and performance anomalous years before Bullrun disclosure
SupportingBernstein, Lange, and Niederhagen's 2015 paper 'Dual EC: A Standardized Back Door' documents that Dual_EC was measurably slower and produced more biased (less random) output than competing NIST-approved generators available at the same time, an engineering anomaly that persisted through NIST, ANSI, and ISO standardization despite offering no technical advantage over alternatives.
Scale of real-world NSA decryption enabled specifically via Dual_EC products remains undisclosed
NeutralWhile the Dual_EC/RSA mechanism and NSA's Sigint Enabling budget are documented, the actual volume of intelligence collected through Dual_EC-equipped commercial products has never been disclosed by the NSA or independently measured, leaving a gap between confirmed capability/intent and confirmed operational impact.
Post-2013 NIST Standards Were Developed With Explicit NSA Exclusion
DebunkingStrongFollowing the Dual_EC controversy, NIST undertook a transparent public process for post-quantum cryptography standardisation (PQC, 2016–2024) that explicitly invited international cryptographic community participation and published all candidate algorithm evaluations. The resulting standards (CRYSTALS-Kyber, CRYSTALS-Dilithium, SPHINCS+) were selected through open competition with no credible evidence of NSA backdooring. Not all encryption standards were compromised by BULLRUN; the programme appears to have targeted specific legacy implementations and certificate-authority relationships rather than mathematics universally.
Evidence Cited by Believers13
NSA budget documents confirm Bullrun programme and its objectives
SupportingStrongNSA budget documents published in the ProPublica/NYT/Guardian joint investigation describe Bullrun as a programme to covertly insert vulnerabilities into commercial encryption systems and influence international standards. The documents are primary-source confirmation.
Dual_EC_DRBG backdoor identified independently by cryptographers in 2007
SupportingStrongDan Shumow and Niels Ferguson presented research at CRYPTO 2007 demonstrating that Dual_EC_DRBG contained a potential backdoor if the elliptic curve constants were chosen with knowledge of a secret discrete logarithm. This independent cryptographic finding predates the Snowden revelations and corroborates the NSA's role.
NIST withdrew Dual_EC_DRBG from guidelines in 2014
SupportingStrongFollowing the Bullrun revelations and cryptographic analysis, NIST withdrew Dual_EC_DRBG from Special Publication 800-90A in 2014. The withdrawal of an official US government standard is a significant institutional acknowledgement of the backdoor concern.
Reuters: RSA received $10 million from NSA to default Dual_EC in BSAFE
SupportingStrongA December 2013 Reuters investigation reported that RSA Security had received a $10 million NSA contract in 2004 to make Dual_EC_DRBG the default random number generator in its BSAFE encryption toolkit, spreading the potentially backdoored generator across commercial and government applications.
Programme represented systematic conflict between NSA's intelligence and security missions
SupportingStrongBullrun highlighted a fundamental institutional tension: the NSA simultaneously advises NIST on cryptographic standards for US government and commercial security while also exploiting weaknesses in those standards for intelligence collection. The conflict of interest is structural and confirmed.
GCHQ Edgehill programme was British parallel to Bullrun
SupportingDocuments in the Snowden archive confirmed that GCHQ operated a parallel programme codenamed Edgehill with similar objectives to Bullrun, confirming the systematic Five Eyes approach to undermining commercial encryption rather than an isolated NSA activity.
Bullrun disclosures accelerated industry movement to verified cryptographic standards
SupportingFollowing the Bullrun revelations, the cryptography and internet standards communities accelerated review of NIST standards with NSA involvement, moved toward algorithm families less susceptible to NSA influence, and strengthened processes for public scrutiny of proposed standards.
Dual EC DRBG Backdoor Mathematically Confirmed
SupportingStrongCryptographers at Microsoft Research (Bernstein, Lange, et al.) published a 2013 paper demonstrating that the Dual Elliptic Curve Deterministic Random Bit Generator contained a verifiable mathematical backdoor: knowledge of the discrete logarithm relationship between two constants would allow complete prediction of outputs. NIST withdrew the algorithm from its Special Publication 800-90A in April 2014 after NSA involvement in setting the constants was established by the Snowden documents.
RSA Security Received $10 Million NSA Contract to Use Dual EC
SupportingStrongReuters reported in December 2013, citing Snowden documents, that RSA Security had accepted a $10 million NSA contract to set Dual EC DRBG as the default random number generator in its BSAFE toolkit. RSA disputed characterization of the arrangement as a secret deal, stating it had relied on NIST's 2006 standardization and the NSA's role as a trusted standards body.
Juniper Networks ScreenOS firewalls found running unauthorized Dual_EC-linked backdoor code (Dec 2015)
SupportingStrongJuniper Networks disclosed that an internal code review found unauthorized code in ScreenOS enabling both administrative-access bypass and passive VPN traffic decryption. CISA issued an out-of-band alert; the VPN-decryption flaw exploited the same Dual_EC_DRBG design weakness at the heart of the RSA/BSAFE Bullrun story, demonstrating the backdoor mechanism was exploitable in a real deployed product, not just a lab construct.
Show 3 more evidence points
Unknown party silently replaced Juniper's self-generated Dual_EC constant in 2012, enabling passive VPN decryption
SupportingStrongCryptographer Matthew Green's analysis and the subsequent peer-reviewed study (Checkoway et al., ACM CCS 2016) found that Juniper's own Dual_EC 'Q' parameter — intended to avoid NSA's default constant — was swapped for an unknown value in 2012 without any other code changes, letting whoever made the swap predict VPN session keys from a small sample of output. This shows a Dual_EC-style backdoor can be silently repurposed by any party able to modify the constant, not only its original designer.
Rebuttal
Attribution for the 2012 change was never established. It is consistent with a nation-state actor exploiting the built-in weakness, but neither Juniper's investigation nor independent researchers identified who made the change, so it cannot be presented as proof of a specific actor's involvement.
NSA's classified 'Sigint Enabling Project' budget documents show sustained, dedicated funding for undermining commercial crypto
SupportingStrongThe 2013 US intelligence 'black budget,' reported by the Guardian, itemised a Sigint Enabling Project costing $254.9 million in FY2013 alone (over ten times PRISM's budget), explicitly tasked with covertly influencing commercial IT product design to make it exploitable, with total Sigint-enabling spending exceeding $800 million since 2011 — establishing Bullrun as an institutionally funded, multi-year effort rather than an isolated Dual_EC incident.
Academic cryptanalysis identified Dual_EC's design as statistically and performance anomalous years before Bullrun disclosure
SupportingBernstein, Lange, and Niederhagen's 2015 paper 'Dual EC: A Standardized Back Door' documents that Dual_EC was measurably slower and produced more biased (less random) output than competing NIST-approved generators available at the same time, an engineering anomaly that persisted through NIST, ANSI, and ISO standardization despite offering no technical advantage over alternatives.
Counter-Evidence6
RSA denied knowing Dual_EC was compromised
DebunkingRSA Security denied that it had knowingly included a backdoored generator in BSAFE, stating it had not been aware of the potential compromise at the time of the contract. The denial raises questions about due diligence given the 2007 public cryptographic research.
Rebuttal
RSA's denial concerns its own knowledge and intent, not the existence of the backdoor or the NSA contract. Independent analysis of the Dual_EC_DRBG constants confirms the mathematical basis for the backdoor regardless of what RSA knew.
Cryptographers Flagged Dual_EC_DRBG Weaknesses in 2007, Before Snowden
DebunkingDan Shumow and Niels Ferguson publicly demonstrated the potential backdoor structure of Dual_EC_DRBG at CRYPTO 2007, six years before the Snowden disclosures. Bruce Schneier and Daniel Bernstein independently noted the anomaly. This means the cryptographic community's self-correcting mechanisms partially worked: the flaw was identified, debated, and Dual_EC was rarely deployed in practice outside RSA Security's BSAFE library. The BULLRUN revelations confirmed what the research community already suspected about that specific algorithm. This limits the claim that NSA systematically subverted crypto standards undetected — at least in this case, the subversion was noticed and flagged by independent researchers operating through normal channels.
Post-Snowden Standards Processes Explicitly Excluded NSA Influence
DebunkingFollowing the 2013 Snowden disclosures, NIST withdrew Dual_EC_DRBG from its recommendations and restructured its cryptographic standards process to increase transparency and external review. The NIST Post-Quantum Cryptography competition (launched 2016) was explicitly designed with open international participation, public comment periods, and cryptanalysis rounds to prevent the kind of opaque insertion alleged with Dual_EC. Widely deployed modern standards — AES-GCM, ChaCha20-Poly1305, X25519 — have been extensively reviewed and show no credible evidence of NSA backdooring. The BULLRUN story, accurately read, is about one specific algorithm and some commercial product influence, not wholesale subversion of all encryption standards.
Cryptographers Publicly Flagged Dual_EC Weakness in 2007, Six Years Before Snowden
DebunkingDan Shumow and Niels Ferguson presented a public analysis at CRYPTO 2007 demonstrating that Dual Elliptic Curve Deterministic Random Bit Generator had a potential backdoor structure if its constants were chosen with knowledge of a discrete logarithm relationship. This was not a secret finding — it was published in conference proceedings and widely discussed in the cryptographic community. The NSA's alleged deliberate insertion of the weakness was exposed through open academic cryptanalysis, not whistleblowing. This demonstrates that the cryptographic peer-review system eventually identified the problem through normal scientific channels.
Post-Snowden NIST Standards Processes Explicitly Excluded NSA Influence
DebunkingFollowing the 2013 Snowden revelations, NIST conducted an internal review, withdrew Dual_EC_DRBG from its standards, and restructured its cryptographic standards process to include external cryptographic experts and increase transparency of deliberations. NIST's post-2015 post-quantum cryptography standardization process explicitly used open international competition with public analysis periods. These institutional reforms directly addressed the vulnerability that BULLRUN revealed. Not all encryption standards are compromised; the post-2013 standards landscape reflects a measurable response to demonstrated NSA overreach.
Post-2013 NIST Standards Were Developed With Explicit NSA Exclusion
DebunkingStrongFollowing the Dual_EC controversy, NIST undertook a transparent public process for post-quantum cryptography standardisation (PQC, 2016–2024) that explicitly invited international cryptographic community participation and published all candidate algorithm evaluations. The resulting standards (CRYSTALS-Kyber, CRYSTALS-Dilithium, SPHINCS+) were selected through open competition with no credible evidence of NSA backdooring. Not all encryption standards were compromised by BULLRUN; the programme appears to have targeted specific legacy implementations and certificate-authority relationships rather than mathematics universally.
Neutral / Ambiguous3
Scope of BULLRUN Remains Classified; Full Impact Unverified
NeutralThe published Snowden documents described BULLRUN in general terms as a program to defeat commercial encryption through multiple methods including insertion of vulnerabilities, exploitation of implementation flaws, and court orders. The full extent of the program — how many standards were compromised, which commercial products were affected — remains classified. Independent security researchers have not been able to confirm NSA access to all systems the program reportedly targeted.
Cryptographers Flagged Dual_EC Weakness Before Snowden
NeutralStrongDan Shumow and Niels Ferguson publicly presented mathematical analysis at CRYPTO 2007 demonstrating that Dual_EC_DRBG's parameters could contain a backdoor if generated by a party who knew the discrete-log relationship. This was six years before Snowden's disclosures. The cryptographic community's self-correcting peer review — not whistleblowing — identified the specific weakness, suggesting the NSA's influence on NIST was exploitable but not impenetrable to scrutiny. NIST withdrew Dual_EC in 2014 following the Snowden context but acting on pre-existing mathematical objections.
Scale of real-world NSA decryption enabled specifically via Dual_EC products remains undisclosed
NeutralWhile the Dual_EC/RSA mechanism and NSA's Sigint Enabling budget are documented, the actual volume of intelligence collected through Dual_EC-equipped commercial products has never been disclosed by the NSA or independently measured, leaving a gap between confirmed capability/intent and confirmed operational impact.
Timeline
NIST publishes SP 800-90 including Dual EC DRBG
The National Institute of Standards and Technology standardizes the Dual Elliptic Curve DRBG algorithm despite objections from cryptographers Dan Shumow and Niels Ferguson who noted the suspicious structure of the curve constants at the CRYPTO 2007 conference.
NIST standardises Dual_EC_DRBG in SP 800-90A
NIST publishes Special Publication 800-90A standardising Dual_EC_DRBG. The standard had been developed with significant NSA input. Cryptographers begin noting anomalies in the elliptic curve constants.
Shumow and Ferguson present Dual_EC backdoor research at CRYPTO 2007
Microsoft cryptographers Dan Shumow and Niels Ferguson present research at the CRYPTO 2007 rump session demonstrating that Dual_EC_DRBG contains a potential backdoor exploitable by anyone knowing a secret discrete logarithm relationship between the algorithm's constants.
Source →ProPublica/NYT/Guardian publish Bullrun joint investigation
The joint investigation publishes NSA budget documents describing Bullrun, including its objectives of inserting vulnerabilities into commercial encryption and influencing standards. The Reuters report on the RSA $10 million contract follows in December 2013.
Source →
Verdict
Confirmed by NSA budget documents in the joint ProPublica/NYT/Guardian September 2013 investigation. Bullrun systematically undermined commercial encryption through standards manipulation (Dual_EC_DRBG/NIST) and industry arrangements. The Dual_EC_DRBG backdoor was identified independently by cryptographers in 2007. NIST withdrew the standard in 2014. Reuters confirmed RSA received $10M from NSA to make Dual_EC the default in BSAFE in December 2013.
Frequently Asked Questions
What is Dual_EC_DRBG and why does it matter?
Dual_EC_DRBG (Dual Elliptic Curve Deterministic Random Bit Generator) is a cryptographic random number generator standardised by NIST in 2006. Cryptographic security depends on unpredictable random numbers; a predictable or backdoored random number generator undermines all cryptography built on it. Microsoft cryptographers demonstrated in 2007 that Dual_EC contained a potential backdoor exploitable by anyone knowing a secret discrete logarithm in the algorithm's constants. Snowden documents indicated the NSA had arranged this.
Did RSA Security knowingly incorporate a backdoored generator?
RSA Security denied that it had knowingly incorporated a backdoor, stating it had not known Dual_EC_DRBG was potentially compromised at the time of its $10 million contract with the NSA. Critics noted that the 2007 cryptographic research identifying the potential backdoor was publicly available well before many BSAFE deployments, raising questions about RSA's due diligence.
What did NIST do after the Bullrun revelations?
NIST reopened Dual_EC_DRBG for public comment following the September 2013 revelations. In April 2014, NIST formally withdrew Dual_EC_DRBG from Special Publication 800-90A. NIST also undertook a broader review of its cryptographic standards development process to strengthen transparency and reduce the potential for external influence on algorithm selection.
What is the conflict of interest at the heart of Bullrun?
Sources
Show 12 more sources
Further Reading
- paperShumow and Ferguson: On the Possibility of a Back Door in the NIST SP800-90 Dual EC PRNG — Dan Shumow, Niels Ferguson (2007)
- articleN.S.A. able to foil basic safeguards of privacy on web (NYT/ProPublica) — Nicole Perlroth, Scott Shane, Jeff Larson (2013)
- articleExclusive: NSA infiltrated RSA security more deeply than thought (Reuters) — Joseph Menn (2013)
- bookData and Goliath: The Hidden Battles to Collect Your Data and Control Your World — Bruce Schneier (2015)