Wired is running an article by Bruce Schneier where he discusses the fact that the Dual_EC-DRBG (dual elliptic curve deterministic random bit generator) function was revealed to have a backdoor capability during the Crypto 2007 conference. Basically, there can exist a set of complements to the elliptic curve parameters that can remove the randomness.

Of course, we have no way of knowing whether the NSA knows the secret numbers that break Dual_EC-DRBG. We have no way of knowing whether an NSA employee working on his own came up with the constants — and has the secret numbers. We don’t know if someone from NIST, or someone in the ANSI working group, has them. Maybe nobody does.

I do know that the NSA has been pushing Suite B cryptography pretty hard, which includes elliptic curve cryptography and as an extension, the core of the Dual_EC-DRBG function. It’s also pretty common knowledge that ECC has been championed by the NSA for a while. Even if it is totally innocent, it still looks bad.