>I would like to open the floor to *informed speculation* about BULLRUN.

Not informed since I don't work for them, but a connect-the-dots:

1. ECDSA/ECDH (and DLP algorithms in general) are incredibly brittle unless
   you get everything absolutely perfectly right.

2. The NSA has been pushing awfully hard to get everyone to switch to

Wasn't Suite B promulgated in the 2005-2006 period?

Peter (who choses RSA over ECC any time, follow a few basic rules and you're
       safe with RSA while ECC is vulnerable to all manner of attacks,
       including many yet to be discovered).

