Dan Boneh: The elliptic curve running the modern internet might have a backdoor [video]
youtube.com
2 threads
Explanation ~15 min in
Gist: the seed for the curve has unknown origin. Possible attack: let's say there is an attack possible on 1/10^6 curves. Just loop through a million curves until you find one vulnerable, and publish it into the standard.