Why should the NSA receive any more scrutiny than anyone else?
The NSA is in a weird position. Their mission is to secure the state and to gain advantage over adversaries. So they have a vested interest in protecting state industry from it's adversaries, and no interest in protecting anyone from themselves.
So with that in mind it's perfectly reasonable for them to try to slip backdoors into anything and everything, and to also prevent others from doing the same.
The same is probably true of every other intelligence agency.
If we start rejecting their contributions by default then they'll just start looking for other ways to exploit the process if they haven't already.
What's to stop them from bribing or extorting independent researchers?
Perhaps there needs to just be a paranoid level of scrutiny over anyone and everything? When securing software you assume every request is threatening, why not when evaluating it?
>Why should the NSA receive any more scrutiny than anyone else?
Because they were caught red-handed. They were effectively proven to have attempted to push a backdoored random number generator as a standard. They were the only ones who possessed the key to the backdoor.
They never suggested that the backdoor (or "key escrow" as they call it) was present in the algorithm. Even the Clipper chip [1], as bad as it was, wasn't this bad, since they were trying to be semi-transparent by saying "we possess the master key to this so we can help law enforcement investigate terrorism and other serious crimes".
Here, the scheme was executed entirely in secret.
If any private person or organization in the US tried to do something like this, they would be arrested and prosecuted under the CFAA (among other things). One could even make an argument that their DRBG backdoor is even more willfully malicious and toxic to our security than the warrantless mass surveillance.
If a conman tries to sell you some phony goods that he knows to be phony, you're never going to buy anything from him again, even if the later stuff seems legit.
What's stopping them, or anyone else, from trying this sort of thing again through an unidentified agent to circumvent the enhanced scrutiny that they would receive otherwise?
By making harder just for the NSA you achieve nothing but a false sense of security.
Instead the process needs to be more rigorous and scrutinized for everyone.
> Why should the NSA receive any more scrutiny than anyone else?
They’re a large, well-funded agency with documented efforts antagonistic to the goals of cryptography. There aren’t that many organisations fitting that bill and submitting designs. It makes sense to give them special attention. Unsaid in this is what prevents the NSA from submitting a scheme through an unaffiliated researcher.
The NSA is in a weird position. Their mission is to secure the state and to gain advantage over adversaries. So they have a vested interest in protecting state industry from it's adversaries, and no interest in protecting anyone from themselves.
So with that in mind it's perfectly reasonable for them to try to slip backdoors into anything and everything, and to also prevent others from doing the same.
The same is probably true of every other intelligence agency.
If we start rejecting their contributions by default then they'll just start looking for other ways to exploit the process if they haven't already.
What's to stop them from bribing or extorting independent researchers?
Perhaps there needs to just be a paranoid level of scrutiny over anyone and everything? When securing software you assume every request is threatening, why not when evaluating it?