Factoring "short-sleeve" RSA keys with polynomials

We found hundreds of weak RSA and DSA keys with biased bits that we could quickly factor using a new polynomial-based cryptanalytic technique.

The Trail of Bits Blog