On Wed, J= an 28, 2015 at 6:14 AM, Stanislav V. Smyshlyaev <smyshsv@gmail.com>= wrote:As we believe (and= as it has been mentioned earlier during discussion at CFRG), the initital = seed value doesn't have to be chosen explicitly in case of trust in bas= ic hash function properties =E2=80=93 to gain some "backdoor-type"= ; properties of the curve with d =3D hash(W), one has either to combine suc= h algebraic properties of a curve with properties of a hash function (for a= trivial example, to have an ability to obtain a hash preimage) or to choos= e a very probable "backdoor-type" property of a curve (such that = it is possible to obtain by random choice of a curve).Hi Stanislav,Dan B= ernstein and Tanja Lange have already demonstrated that such "verifiab= ly random" generation procedures can be used to surreptitiously tweak = specific curve parameters:I for one would not feel particularl= y inclined to trust a curve generated with this method, and would personall= y prefer the sort of rigid curve generation approach that this committee an= d others have been working on to any curve with large unexplained mystery c= onstants.

