An attacker can impersonate a web site or possibly decrypt encrypted traffic to that web site. The problem mainly affects embedded devices such as routers and VPN devices, not full-blown web servers. We suspect that more than 200,000 devices, representing 4.1% of the SSL keys in our dataset, were generated with poor entropy. Only one of the factorable SSL keys was signed by a trusted certificate authority and it has already expired. There are signed certificates using repeated keys; some of them are generated by vulnerable devices. Some of these are due to website owners submitting known weak keys to be signed.”]

