Skip to main content

Fact check

Is it true: Bullrun: NSA crypto-undermining + Dual_EC_DRBG backdoor (revealed Sept 2013)?

Confirmed5% confidence

Yes — this is confirmed.

Confirmed by NSA budget documents in the joint ProPublica/NYT/Guardian September 2013 investigation. Bullrun systematically undermined commercial encryption through standards manipulation (Dual_EC_DRBG/NIST) and industry arrangements. The Dual_EC_DRBG backdoor was identified independently by cryptographers in 2007. NIST withdrew the standard in 2014. Reuters confirmed RSA received $10M from NSA to make Dual_EC the default in BSAFE in December 2013.

The claim

Revealed in September 2013 by a joint ProPublica, New York Times, and Guardian investigation using Snowden documents, Bullrun was a classified NSA programme to covertly undermine encryption standards,

Key evidence

NSA budget documents confirm Bullrun programme and its objectives

RSA denied knowing Dual_EC was compromised

Read the full evidence file

Conspirafy steelmans each claim, then follows the evidence. How we reach a verdict · Check another claim