Reuters reported that NSA penetration into RSA is more in-depth than previously thought. It is not embedded in RSA's encryption product with a pseudo-random generator with a backdoor, but two. In addition to the well-known Dual EC_DRBG Dual elliptic curve deterministic Random bit generator, there is also Extended Random. In theory, Extended Random, as the second Random source, can make the encryption key safer.
However, Professor Matt Green, an expert in encryption at the University of John hopks', pointed out in an upcoming study that, with the help of Extended Random, attackers can crack the RSA dual-elliptic curve encryption software password tens of thousands of times faster.
NSA plays an important role in the development of the Extended Random protocol. One of the Protocol authors, Margaret Salter, was a technical director of NSA and currently works in Mozilla, he and Mozilla both refuse to comment. Extended Random was first promoted to enhance the randomness of Random numbers generated by the double elliptic curve algorithm. Professor Green said that using Dual EC_DRBG is like playing with fire, and using Extended Random is like pouring gasoline on your own.