> > It is probably very difficult, possibly impossible in practice, to
> > backdoor a symmetric cipher. For evidence, I direct you to this
> > old paper by Blaze, Feigenbaum and Leighton:
> > http://www.crypto.com/papers/mkcs.pdf
> There is also a theorem somewhere (I am forgetting where)

See the URL quoted above. That is the implication of their paper.

> that says that if you have a block cipher with a back door, then it
> is also a public key cipher.

