RSA SECURITY▊
The cryptography company that shipped a suspected NSA backdoor as its default random number generator — and, per Reuters, was paid $10 million to do it. RSA denies the deal ever had that shape.
- OPERATION
- Cryptography — the BSAFE toolkit embedded in thousands of products, plus the industry's flagship conference bearing its name
- ALGORITHM
- Dual_EC_DRBG — the BSAFE default RNG from 2004; publicly flagged as a possible trapdoor in 2007; withdrawn by NIST in 2014 FACT
- EVENT
- $10M NSA CONTRACT ALLEGED — Reuters, December 2013, citing sources familiar with the contract ATTRIBUTED
- DENIAL
- "We have never entered into any contract… with the intention of weakening RSA's products" — RSA, on the record, December 2013 FACT-OF-DENIAL
- DISPOSITION
- Never adjudicated. No lawsuit, no regulator finding, no retraction by Reuters, no suit by RSA against Reuters. A standoff, standing since 2013 FACT
Here is the locksmith of the industry — the animal whose name is on the padlock icon itself — observed shipping, as its factory setting, the one lock the whole field had publicly wondered about since 2007. Whether it was paid to choose that lock is the part still in dispute. That it chose it, and kept choosing it, is not.
Official channel: x.com/@RSAsecurity — the company's X account. FIRST-PARTY
"We have never entered into any contract or engaged in any project with the intention of weakening RSA's products, or introducing potential 'backdoors' into our products for anyone's use." — RSA, official statement, December 2013, in response to the Reuters story. The full statement, preserved from the company's own blog, is in the locker.
Read the denial the way a cryptographer reads a protocol: it denies intent, not the contract, not the money, not the default. Ars Technica filed it, in as many words, as a "non-denying denial." That is an observation about sentence construction, and it cuts precisely as far as sentence construction cuts — a company under this kind of fire drafts through counsel, and counsel writes narrowly for many innocent reasons.
What the archive can hold as fact is smaller and harder: the algorithm was weak, the weakness was the kind only its designer could use, RSA shipped it as the default for nine years, and the U.S. government's own standards body eventually killed it. The $10 million is Reuters' word against RSA's. Both words are below, at full strength.
the drama timeline
ACT I — THE DEFAULT (2004–2007)
Every cryptosystem stands on its randomness. Choose the random number generator and you have chosen everything downstream. In 2004, RSA chooses.
-
2004–2006
Dual_EC becomes the factory setting
RSA adopts Dual_EC_DRBG as the default RNG in BSAFE — by its own later account, in 2004, before NIST standardized the algorithm in SP 800-90 (2006). The NSA had championed the algorithm's standardization. BSAFE's reach means the default propagates silently into thousands of downstream products.
-
AUG 2007
The trapdoor, described on stage
At the CRYPTO 2007 rump session, Microsoft's Shumow and Ferguson demonstrate that Dual_EC_DRBG's published constants could be related to a second, secret set of numbers — and whoever held those numbers could predict the generator's output. Nobody outside the constants' author could prove or disprove it. The field's suspicion becomes permanent. The default does not change.
From 2007 forward, the question was never whether the lock was strong. It was who else might have a key. The industry kept installing the lock anyway, because it came pre-fitted in the box.
ACT II — SNOWDEN SEASON (SEP–DEC 2013)
The documents arrive, and a six-year-old rump-session slide becomes the most consequential piece of cryptanalysis of the decade.
-
SEP 2013
RSA tells customers to stop using its own default
After reporting on the Snowden documents places Dual_EC_DRBG at the center of the NSA's program to weaken cryptographic standards, and NIST reopens its standard, RSA advises developers to stop using the default RNG in BSAFE — the setting it had shipped for nine years.
-
DEC 20, 2013
Reuters: the $10 million contract
Reuters (Joseph Menn) reports that the NSA paid RSA $10 million under a secret contract to make Dual_EC_DRBG the BSAFE default — citing sources familiar with the contract. The Register's framing of the arithmetic: the sum equaled more than a third of the BSAFE division's annual revenue. The sources are anonymous; no contract document has ever been published.
-
DEC 22, 2013
The denial
RSA answers on its corporate blog: it "categorically" denies the allegation, has "never entered into any contract or engaged in any project with the intention of weakening RSA's products," made the 2004 decision "in the context of an industry-wide effort to develop newer, stronger methods," and notes its NSA relationship was never secret — it works with the agency "both as a vendor and an active member of the security community." Ars Technica's assessment of the drafting: a "non-denying denial" — it denies intent, while the money and the contract go unaddressed.
ACT III — THE RECKONING (2014)
The field renders the only verdicts available to it: speakers walk, researchers publish, and the standards body quietly buries the algorithm.
-
DEC 2013–FEB 2014
The conference boycott
Mikko Hyppönen of F-Secure publicly cancels his RSA Conference talk over the Reuters report, in an open letter to the chiefs of EMC and RSA; other speakers follow, and a counter-event (TrustyCon) forms across the street. The conference proceeds — at full commercial strength.
-
MAR 31, 2014
Extended Random
Reuters reports the findings of an academic team (Checkoway et al.): BSAFE-Java also implemented Extended Random, an NSA-promoted TLS extension that, in their analysis, would have sped up exploitation of a Dual_EC backdoor by orders of magnitude. RSA says the extension was never enabled by default and had been removed. The researchers' full technical record lives at projectbullrun.org.
-
APR 21, 2014
NIST kills the algorithm
NIST removes Dual_EC_DRBG from SP 800-90A and advises everyone still using it to transition off "as quickly as possible." The U.S. government's own standards body, closing the file on the U.S. government's own algorithm.
This is the one adjudication the record contains, and it is of the algorithm, not the vendor. The lock was bad. Who paid whom to fit it remains exactly where Reuters and RSA left it.
both sides, on the record
The default was real and it was theirs. RSA shipped Dual_EC_DRBG as BSAFE's factory setting from 2004 to 2013 — through six years of standing public suspicion after Shumow–Ferguson [1] [7].
The reporting has held for over a decade. Reuters' $10M story was never retracted, and RSA — which had every incentive and resource — never sued over it [1].
The denial is narrow. It denies intent to weaken; it does not deny the contract or the payment. Ars called it a non-denying denial at the time [3] [4]. And the algorithm itself was, in the end, formally withdrawn as unsafe [6].
The charge rests on anonymous sources. No contract has ever been published, no whistleblower has gone on the record, and no court, regulator, or committee has ever adjudicated the claim — in twelve years [1].
The timeline defense is coherent. RSA says it adopted Dual_EC in 2004 — two years before NIST standardized it and three before the trapdoor demonstration — when elliptic-curve methods were the industry's direction, and that it relied on NIST's continuing endorsement, as did the rest of the field. When NIST's guidance changed in 2013, RSA advised customers off the algorithm [3] [5].
The denial, at full strength: "We have never entered into any contract or engaged in any project with the intention of weakening RSA's products, or introducing potential 'backdoors' into our products for anyone's use" — and the NSA relationship, RSA notes, was never a secret in the first place [3].
YOU DECIDE
Scoped to the claims. That Dual_EC_DRBG was weak, that RSA shipped it as the default for nine years, and that NIST withdrew it are facts. That the NSA paid $10 million for the default is Reuters' reporting — unretracted, unlitigated, and unproven. Weigh the two silences: RSA never sued the wire service that accused it, and no document ever surfaced to convict it.
The archive does not judge. It keeps both statements, side by side, where they have glared at each other since 2013.
evidence locker
THE ALLEGATION & THE ANSWER
EXPERTS & PRESS
projectbullrun.org — the Dual EC research record (Checkoway, Green, et al.) ATTRIBUTED — the consolidated academic analysis, including Extended Random.
projectbullrun.org/dual-ec/
SUBJECT'S OWN CHANNELS
X — @RSAsecurity (official account) FIRST-PARTY — account-level link only; no fabricated permalinks.
x.com/RSAsecurity
The standard. The central charge on this sheet is an allegation and is labeled as one: Reuters' reporting, from anonymous sources, never adjudicated by any court or regulator, and categorically denied by RSA. The facts stated as facts — the default, the dates, the 2007 warning, NIST's withdrawal — are sourced to the company's own statements, the academic record, and the standards body. The defense, including RSA's full denial and its timeline argument, is presented at full strength. No intent is asserted, no motive diagnosed. The burden of proof is on us, not the subject. If it couldn't survive a defamation challenge, it wouldn't be on this page.