2018.08.19 20:37:07 (1031248713623035905) from Daniel J. Bernstein:
Unlike https://eprint.iacr.org/2018/749.pdf, I recommend: 1. Require+verify DH primality proofs, as in https://cr.yp.to/ecdh/curve25519-20051115.pdf and https://safecurves.cr.yp.to/primeproofs.html. 2. Standardize primes so this is cheap. 3. Ignore nitwits writing "the appendix that shows that 3 numbers are prime should be removed."
2018.08.22 22:01:11 (1032357034262376448) from Daniel J. Bernstein:
The quote is excerpted from the entertaining collection of anonymous reviews of the original Curve25519 paper. See https://cr.yp.to/talks.html#2016.03.09 for more.