Reasonably efficient quantum attack on the primitive (which supports 3000-10000 bits as public key)
Are we meant to assume from dates that this happened that they now own TLS which manages 1024-2048 bits for the public key or just that they're not very good at rolling their own security?