https://weakdh.org/ really cute shit
(like people say you can pull log q bits there are papers on it but i don't just trust anything i read because it says diffie-hellman on it)
but i cannot tell you how my jaw dropped to learn elliptic curves and lattices are quite literally the two components of the techniques used against discrete log in diffie-hellman. very literally
this is the one i found most useful to understand it (this is not the quadratic/number field sieve method, btw, that just runs to factor your q - 1 afaict):
A.K. Lenstra, H.W. Lenstra, Jr., L. Lovasz: Factoring Polynomials with Rational Coefficients
there's a book by lenstra on the number field sieve with a surprise visit by daniel jackoff bernstein in the credits but i haven't read it because i don't really care that much and as far as i'm aware you can in fact just delegate to the hardness of discrete log and feel satisfied that you are not going to die horribly. ECC does not give you that