It doesn't really matter whether we use the full field or not (as long as `z != 0`), but it makes various scalar mults cheaper. _Originally posted by @str4d in https://github.com/zkcrypto/bellman/pull/59#discussion_r569020447_
It doesn't really matter whether we use the full field or not (as long as
z != 0), but it makes various scalar mults cheaper.Originally posted by @str4d in #59 (comment)