[curves] Another try at point compression

David Leon Gil coruus at gmail.com
Sun Dec 14 17:08:58 PST 2014

On Sun, Dec 14, 2014 at 3:36 PM, Michael Hamburg <mike at shiftleft.org> wrote:
> The main advantage vs Montgomery x + Edwards x sign is that the encoding I’m working on eliminates the cofactor for most practical purposes.
. . .
> * the isogenous twisted Edwards curve with a’ = -1, d’ = d-1 effectively has complete addition formulas;
> * the wire format supports precisely those points which can actually come out of a legitimate implementation.

These advantages strike me as rather decisive: I'd anticipate
implementers being tempted by the performance of the twisted curve.

