Bruce Schneier recommends against using them.
Bruce Schneier recommends against using them.
Regardless, I'm not suggesting new cryptosystems should use the NIST P-curves. They shouldn't; those curves are just as tricky to use as RSA.
[1]: http://blog.cryptographyengineering.com/2015/10/a-riddle-wra...
If so, use NaCl/libsodium at the application layer and don't rely on ECDSA alone.
If your threat model is "criminals", ECDSA is less insane than RSA (provided, once again, you're not implementing it yourself, you're relying on developed by a team of cryptographers and security engineers).
My threat model includes NSA dragnets but not being specifically targeted by the NSA.
That term likely means one of two things: guarding against a particularly capable attacker or paranoia for others