Rumor has it that certain government applications do Diffie Hellman with 2K-bit moduli. Given the apparent connections between factoring and discrete logarithm (the complexity formulas seem to look very much alike), it appears that at least one user feels that keys longer than 1K bits provide a desirable safety margin. Phil