In December 2013, RSA was accused – based on documents leaked by Edward Snowden – of entering into a secret $10 million deal with the NSA to use a flawed type of encryption in its products, but a backdoor may not be the only hidden means, according to researchers from several universities.
According to researchers from Johns Hopkins University, the University of Wisconsin, Eindhoven University of Technology, and the University of California, San Diego, “Evidence of a research into a non-standard TLS extension, called “Extended Random” was discovered in RSA BSAFE products.”
In September 2013, the National Institute of Standards and Technology (NIST), as well as RSA, declared against the use of the Dual Elliptic Curve Deterministic Random Bit Generator (Dual_EC_DRBG) algorithm, because it contained a backdoor. All versions of RSA's BSAFE Toolkits were affected.

