Fallacy of encryption: the algorithms are secure, it is the random numbers that are backdoored, but you cannot ever prove that.
--> How? The random numbers that servers use are chosen from a list if you will as opposed to true zener diode type shit.
You cannot prove this, but this is how I would do it if asked, and I am pretty sure RSA does this if not mistaken.