Comment by patrakov
Ed25519 is not just about performance. It, unlike other elliptic crypto, was explicitly constructed to avoid data-dependent branches and memory access patterns that could be exploited as side channels via timing.
Ed25519 is not just about performance. It, unlike other elliptic crypto, was explicitly constructed to avoid data-dependent branches and memory access patterns that could be exploited as side channels via timing.