The WeakDH team showed (in 2015) that Diffie-Hellman key exchange with prime number groups of 1024 bits or less were weaker than we previously thought, and well within the reach of nation states. They recommended (in 2015) using 2048-bit or higher prime groups. The SSH audit project recommends that we should use 3072-bit now. See: See: