It is complicated, and, on top of that, does not win in application to the sizes of integer typically used in crypto. Which is why I did not use it (or any other "heavies", e.g. Strassen's, Fuhrer's, etc) in FFA.
Re: FFT: A hypothetical constant-time FFT multiplier would be interesting. AFAIK there is not an approach known to this.
]]>