Alfred Menezes has drawn my attention to a new website. It gathers together all the Koblitz-Menezes papers critiquing provable security:
There is plenty of stuff in these papers about elliptic curves and elliptic curve public key cryptography.
The papers contain a number of interesting remarks and valid points. But there is plenty to argue about and disagree with as well. They are great papers to read in a group of crypto researchers/students.
— Steven Galbraith