To deal with different ways of encoding compressed curve points for 25519 and p256, I introduced the function xC2xyC that converts (the octet representation) of an x-coordinate of an EC point to (the …
"otherwise you get into weird issues with the RO proof of pseudorandomness not composing for multiple copies of the same VRF with different PKs, because you have to program the RO in different ways th…