Update: see this post for a real world protocol that is broken if Curve25519 public keys are not validated.
Why not validate Curve25519 public keys could…
Update: see this post for a real world protocol that is broken if Curve25519 public keys are not validated.