> But my awareness of ECC issues is that the constants are suspicious
> according to this web page: http://safecurves.cr.yp.to/rigid.html

See also:


This is a demonstration of how even though a "verifiably random" process
(used by the NIST, Brainpool, and the GOST curves) is used, it's possible
to tamper with curve parameters.

BADA55's tampering was not malicious (and in fact they are "safe curves"
per safecurves.cr.yp.to), but the possibility to tamper with curve
parameters exists in any curves generated this way.

This is why "nothing up my sleeve" curve constants generated through a
rigid process are important (per your link).

