Diffie-Hellman deployment in practice
I 23.9% of 14.3M HTTPS servers support Diffie-Hellman
I Observed 70,000 distinct primes p
I Found 4800 groups (p, g) where (p − 1)/2 was not prime.
I Applied ECM to opportunistically factor (p − 1)/2.
I Learned prime factors of order of g for 750 groups, used in
40,000 connections across our Internet scans.
For random p, p − 1 likely to have large factors, so might not
recover full discrete log