Dear Ron,
> One of the motivations for using curve25519 is supposedly its transparency in
> terms of not having any weird parameters of unknown provenance that could
> conceal weaknesses. But there is one weird number in the curve25519 spec,
> the coefficient of x^2, which is 486662. That number seems to have been
> pulled out of a hat. The only condition on it is that A^2-4 is not a square
> in 2^255-19. But 486662 is far from the smallest number that meets that
> conditions. That would be (AFAICT) 5. So why 486662?
>
You also need tht the curve is cryptographically secure.
Please check out
http://safecurves.cr.yp.to/rigid.html
All the best
Tanja
_______________________________________________
Curves mailing list
[email protected]
https://moderncrypto.org/mailman/listinfo/curves