[cryptography] What's the point of using non-NIST ECC Curves?

> However, both scenarios (NSA engineered them to be bad, NSA engineered
> them to be good) mean that the NSA knows a great deal more about weaknesses
> in Elliptic Curve Cryptography than we do. Doesn't that give you great
> pause in using the algorithm at all?

Sure, that's why djb and friends are also working on implementing McEliece
and Merkle signatures

