RSA was not "Duped" - they wilfully *REMOVED* their existing RNG code and **REPLACED** it with Dual_EC_DRBG.  No security programmer would *EVER* do that, when the usual way of folding in new random sources is XOR (so you get the strengths of all, and the weaknesses of none).RSA knew *EXACTLY*...