NSA has a patent on ECC, expects licenses for commercial use, and has some kind of conditions you must adhere to
My presumption was that you were referring to patents assigned to NSA. NSA had patents relevant to number theoretic crypto. They're long-expired.
Apparently, what you actually meant was:
NSA has licensed a patent now owned by Blackberry.
What this has to do with open source ECC software, you have not made clear. Nobody is talking about using MQV.
It had never occurred to me that I'd sold a company that came within a factor of 7 of the value of Certicom's ECC patents. I did better than I thought I did! Woohoo!
RSA is significantly less safe than ECC alternatives. The situation is not as clear with DH, but it is if you just use Curve25519; Curve25519 is much safer than multiplicative group DH.