[cryptography] regarding the NSA crypto "breakthrough"

James A. Donald wrote:

> Time to generate and select new elliptic curves by an open process,
> wherein any large random quantities are chosen by a non secret process,
> such as searching for the appropriate value nearest a round number.

There are curves not selected by e.g. NIST with a published rationale for
their selection, like Curve25519. Is there any reason why such curves can't
be evaluated retroactively?


See in particular Theorem 2.1.

Tony Arcieri


