Cheaper DNS-on-ENS, by picking the right primitive
Here’s a small decision I’m still fond of.
At Unstoppable Domains I was tokenizing DNS names, actual .com names, onto ENS. To pull that off on-chain you’ve got to verify a DNSSEC signature, and on-chain signature verification is exactly where your gas quietly vanishes.
The oracle let me pick my algorithm: P-256 or RSA. I wanted P-256. Smaller signatures, more modern, obviously the better one, right? Nope. The EVM had no precompile for P-256 back then, so verifying it meant doing the elliptic-curve math by hand in Solidity, and that’s about as pricey as on-chain work gets.
RSA felt like the dusty, boring pick. But RSA really just boils down to one big modular exponentiation, and the EVM’s had a precompile for that since Byzantium. So the “worse” algorithm had a fast lane and the “better” one was stuck walking.
I took the fast lane. Gas per verification dropped two to three times, which stacks up quick when every name someone mints pays it.
Years later P-256 finally got its own precompile, in EIP-7951. If I were doing it today I’d probably take P-256. Back then, modexp was the cheap path.