NSA is known for breaking cryptosystems with implementation flaws, side channels, the bleeding edge of cryptanalysis (which in cases of things like padding oracles and chaining modes make practical differences), and by brute force (when key sizes are within their top notch cracking capability). Furthermore they are known to have sabotaged software to insert exploitable flaws and the CIA today will compromise compilers of specific individuals so that they compile backdoored binaries. Unlikely then, but replacing a popular hosted binary wouldn't have been beyond their capability.
It's not that unlikely they could crack some instances of PGP some of the time. Today the NSA docs reference being able to crack things like OTR sometimes, though unlikely.
Comments
NSA is known for breaking cryptosystems with implementation flaws, side channels, the bleeding edge of cryptanalysis (which in cases of things like padding oracles and chaining modes make practical differences), and by brute force (when key sizes are within their top notch cracking capability). Furthermore they are known to have sabotaged software to insert exploitable flaws and the CIA today will compromise compilers of specific individuals so that they compile backdoored binaries. Unlikely then, but replacing a popular hosted binary wouldn't have been beyond their capability.
It's not that unlikely they could crack some instances of PGP some of the time. Today the NSA docs reference being able to crack things like OTR sometimes, though unlikely.