recent DH change does not avoid *all* possible small-subgroup attacks;