The cr.yp.to microblog: 2015.12.06 00:42:40

2015.12.06 00:42:40 (673286394261987329) from Daniel J. Bernstein:

Curve25519 is conservative prime-field ECDH. Faster _non-conservative_ DH isn't news: first software online in 2006! http://cr.yp.to/talks.html#2006.09.20

2015.12.06 00:51:36 (673288643361054720) from Daniel J. Bernstein:

Best option known for non-conservative ECDH is Kummer: https://eprint.iacr.org/2014/134 https://eprint.iacr.org/2014/379 FourQ is similar speed but patented.