Duplicate Tor's constant-time and small-subgroup-check behavior in ntor code
While I still doubt that these issues are exploitable against ntor as instantiated in tor with curve25519, we might as well duplicate Tor's belt-and-suspenders checks here (in case I'm wrong).