Should we also optimize ECB mode for parallel processing?
I've noticed that users might make uneducated decision to use ECB for benchmarking different libraries against each other, even though ECB may be left intentionally unoptimized for parallel processing (like in libgcrypt now). Optimization in ECB would allow it to better mirror performance expected from modern AEAD modes (eg OCB).