Puts on aluminium hat
Because they're payed by the NSA
Puts off aluminium hat
I'm pretty sure the risk for low-order points can probably be mitigated?
Personally I'd very much like to use Ed25519. I'd also rather use Ed448-Goldilocks. But if EdDSA is going to get used in practice, I'm sure browsers will refuse to add Ed448-Goldilocks support as they decide for their users "it's unnecessary" et cetera..
Also, Let's Encrypt is "bound" to the features offered by their HSMs, so I don't even know if LE could support EdDSA, even if they wanted to..
vvv I trust neither of those.