According to Bernstein it's patent FUD (expired, ancient and solid prior
art).
http://lists.randombit.net/pipermail/cryptography/2013-August/005126.html
Adam
On Fri, Mar 21, 2014 at 12:33:57PM +0100, Mike Hearn wrote:
Oh, one other reason I found - apparently RIM, at least in the past,
has been telling CA's that they need to pay mad bux for the Certicom
ECC patents. So that's another reason why most certs are still using
RSA.