[math-fun] How a weak NIST backdoors Diffie-Hellman