elliptic curves - Who uses Dual_EC_DRBG? - Cryptography Stack Exchange: Even before the potential backdoor was discovered back in 2007, the Dual_EC_DRBG was known to be much slower and slightly more biased than all the other random number generators in NIST SP 800-90. To quote Bruce Schneier: