RSA SECURITY

The cryptography company that shipped a suspected NSA backdoor as its default random number generator — and, per Reuters, was paid $10 million to do it. RSA denies the deal ever had that shape.

OPERATION
Cryptography — the BSAFE toolkit embedded in thousands of products, plus the industry's flagship conference bearing its name
ALGORITHM
Dual_EC_DRBG — the BSAFE default RNG from 2004; publicly flagged as a possible trapdoor in 2007; withdrawn by NIST in 2014 FACT
EVENT
$10M NSA CONTRACT ALLEGED — Reuters, December 2013, citing sources familiar with the contract ATTRIBUTED
DENIAL
"We have never entered into any contract… with the intention of weakening RSA's products" — RSA, on the record, December 2013 FACT-OF-DENIAL
DISPOSITION
Never adjudicated. No lawsuit, no regulator finding, no retraction by Reuters, no suit by RSA against Reuters. A standoff, standing since 2013 FACT

Here is the locksmith of the industry — the animal whose name is on the padlock icon itself — observed shipping, as its factory setting, the one lock the whole field had publicly wondered about since 2007. Whether it was paid to choose that lock is the part still in dispute. That it chose it, and kept choosing it, is not.

Official channel: x.com/@RSAsecurity — the company's X account. FIRST-PARTY

"We have never entered into any contract or engaged in any project with the intention of weakening RSA's products, or introducing potential 'backdoors' into our products for anyone's use." — RSA, official statement, December 2013, in response to the Reuters story. The full statement, preserved from the company's own blog, is in the locker.

Read the denial the way a cryptographer reads a protocol: it denies intent, not the contract, not the money, not the default. Ars Technica filed it, in as many words, as a "non-denying denial." That is an observation about sentence construction, and it cuts precisely as far as sentence construction cuts — a company under this kind of fire drafts through counsel, and counsel writes narrowly for many innocent reasons.

What the archive can hold as fact is smaller and harder: the algorithm was weak, the weakness was the kind only its designer could use, RSA shipped it as the default for nine years, and the U.S. government's own standards body eventually killed it. The $10 million is Reuters' word against RSA's. Both words are below, at full strength.

the drama timeline

ACT I — THE DEFAULT (2004–2007)

Every cryptosystem stands on its randomness. Choose the random number generator and you have chosen everything downstream. In 2004, RSA chooses.

  1. 2004–2006

    Dual_EC becomes the factory setting

    RSA adopts Dual_EC_DRBG as the default RNG in BSAFE — by its own later account, in 2004, before NIST standardized the algorithm in SP 800-90 (2006). The NSA had championed the algorithm's standardization. BSAFE's reach means the default propagates silently into thousands of downstream products.

  2. AUG 2007

    The trapdoor, described on stage

    At the CRYPTO 2007 rump session, Microsoft's Shumow and Ferguson demonstrate that Dual_EC_DRBG's published constants could be related to a second, secret set of numbers — and whoever held those numbers could predict the generator's output. Nobody outside the constants' author could prove or disprove it. The field's suspicion becomes permanent. The default does not change.

    From 2007 forward, the question was never whether the lock was strong. It was who else might have a key. The industry kept installing the lock anyway, because it came pre-fitted in the box.

ACT II — SNOWDEN SEASON (SEP–DEC 2013)

The documents arrive, and a six-year-old rump-session slide becomes the most consequential piece of cryptanalysis of the decade.

  1. SEP 2013

    RSA tells customers to stop using its own default

    After reporting on the Snowden documents places Dual_EC_DRBG at the center of the NSA's program to weaken cryptographic standards, and NIST reopens its standard, RSA advises developers to stop using the default RNG in BSAFE — the setting it had shipped for nine years.

  2. DEC 20, 2013

    Reuters: the $10 million contract

    Reuters (Joseph Menn) reports that the NSA paid RSA $10 million under a secret contract to make Dual_EC_DRBG the BSAFE default — citing sources familiar with the contract. The Register's framing of the arithmetic: the sum equaled more than a third of the BSAFE division's annual revenue. The sources are anonymous; no contract document has ever been published.

  3. DEC 22, 2013

    The denial

    RSA answers on its corporate blog: it "categorically" denies the allegation, has "never entered into any contract or engaged in any project with the intention of weakening RSA's products," made the 2004 decision "in the context of an industry-wide effort to develop newer, stronger methods," and notes its NSA relationship was never secret — it works with the agency "both as a vendor and an active member of the security community." Ars Technica's assessment of the drafting: a "non-denying denial" — it denies intent, while the money and the contract go unaddressed.

ACT III — THE RECKONING (2014)

The field renders the only verdicts available to it: speakers walk, researchers publish, and the standards body quietly buries the algorithm.

  1. DEC 2013–FEB 2014

    The conference boycott

    Mikko Hyppönen of F-Secure publicly cancels his RSA Conference talk over the Reuters report, in an open letter to the chiefs of EMC and RSA; other speakers follow, and a counter-event (TrustyCon) forms across the street. The conference proceeds — at full commercial strength.

  2. MAR 31, 2014

    Extended Random

    Reuters reports the findings of an academic team (Checkoway et al.): BSAFE-Java also implemented Extended Random, an NSA-promoted TLS extension that, in their analysis, would have sped up exploitation of a Dual_EC backdoor by orders of magnitude. RSA says the extension was never enabled by default and had been removed. The researchers' full technical record lives at projectbullrun.org.

  3. APR 21, 2014

    NIST kills the algorithm

    NIST removes Dual_EC_DRBG from SP 800-90A and advises everyone still using it to transition off "as quickly as possible." The U.S. government's own standards body, closing the file on the U.S. government's own algorithm.

    This is the one adjudication the record contains, and it is of the algorithm, not the vendor. The lock was bad. Who paid whom to fit it remains exactly where Reuters and RSA left it.

both sides, on the record

The default was real and it was theirs. RSA shipped Dual_EC_DRBG as BSAFE's factory setting from 2004 to 2013 — through six years of standing public suspicion after Shumow–Ferguson [1] [7].

The reporting has held for over a decade. Reuters' $10M story was never retracted, and RSA — which had every incentive and resource — never sued over it [1].

The denial is narrow. It denies intent to weaken; it does not deny the contract or the payment. Ars called it a non-denying denial at the time [3] [4]. And the algorithm itself was, in the end, formally withdrawn as unsafe [6].

The charge rests on anonymous sources. No contract has ever been published, no whistleblower has gone on the record, and no court, regulator, or committee has ever adjudicated the claim — in twelve years [1].

The timeline defense is coherent. RSA says it adopted Dual_EC in 2004 — two years before NIST standardized it and three before the trapdoor demonstration — when elliptic-curve methods were the industry's direction, and that it relied on NIST's continuing endorsement, as did the rest of the field. When NIST's guidance changed in 2013, RSA advised customers off the algorithm [3] [5].

The denial, at full strength: "We have never entered into any contract or engaged in any project with the intention of weakening RSA's products, or introducing potential 'backdoors' into our products for anyone's use" — and the NSA relationship, RSA notes, was never a secret in the first place [3].

YOU DECIDE

Scoped to the claims. That Dual_EC_DRBG was weak, that RSA shipped it as the default for nine years, and that NIST withdrew it are facts. That the NSA paid $10 million for the default is Reuters' reporting — unretracted, unlitigated, and unproven. Weigh the two silences: RSA never sued the wire service that accused it, and no document ever surfaced to convict it.

The archive does not judge. It keeps both statements, side by side, where they have glared at each other since 2013.

evidence locker

THE ALLEGATION & THE ANSWER

  1. The Register — "How much did NSA pay to put a backdoor in RSA crypto? Try $10m — report" (Dec 21, 2013) ATTRIBUTED — the Reuters exclusive, its sourcing, and the revenue arithmetic. theregister.com/2013/12/21/nsa_paid_rsa_10_million/
  2. Reuters — "Exclusive: NSA infiltrated RSA security more deeply than thought — study" (Mar 31, 2014; archived) ATTRIBUTED — the Extended Random follow-up. web.archive.org/web/20231008142956/…reuters.com…idUSBREA2U0TY20140331
  3. RSA — official response to the Reuters story (Dec 2013; archived from blogs.rsa.com) SELF-PUBLISHED — the categorical denial, in the company's own words. web.archive.org/web/20170830205853/https://blogs.rsa.com/rsa-response/

EXPERTS & PRESS

  1. Ars Technica — "RSA issues non-denying denial of NSA deal to favor flawed crypto code" (Dec 2013) ATTRIBUTED — the parsing of the denial. arstechnica.com/information-technology/2013/12/rsa-issues-non-denying-denial-…
  2. Ars Technica — "Stop using NSA-influenced code in our products, RSA tells customers" (Sep 2013) ATTRIBUTED — the advisory that ended the default. arstechnica.com/information-technology/2013/09/stop-using-nsa-influence-code-…
  3. NIST — "NIST Removes Cryptography Algorithm from Random Number Generator Recommendations" (Apr 2014) FACT — the withdrawal of Dual_EC_DRBG. nist.gov/news-events/news/2014/04/nist-removes-cryptography-algorithm-…
  4. projectbullrun.org — the Dual EC research record (Checkoway, Green, et al.) ATTRIBUTED — the consolidated academic analysis, including Extended Random. projectbullrun.org/dual-ec/
  5. Ars Technica — "Prestigious speaker Mikko Hyppönen cancels RSA talk to protest NSA deal" (Dec 2013) ATTRIBUTED — the boycott. arstechnica.com/information-technology/2013/12/prestigious-speaker-mikko-hypponen-…

SUBJECT'S OWN CHANNELS

  1. X — @RSAsecurity (official account) FIRST-PARTY — account-level link only; no fabricated permalinks. x.com/RSAsecurity
The standard. The central charge on this sheet is an allegation and is labeled as one: Reuters' reporting, from anonymous sources, never adjudicated by any court or regulator, and categorically denied by RSA. The facts stated as facts — the default, the dates, the 2007 warning, NIST's withdrawal — are sourced to the company's own statements, the academic record, and the standards body. The defense, including RSA's full denial and its timeline argument, is presented at full strength. No intent is asserted, no motive diagnosed. The burden of proof is on us, not the subject. If it couldn't survive a defamation challenge, it wouldn't be on this page.