* Most rotary ciphers, such as the [[Enigma machine]].
* RSA keys weaker than 2048 bits.{{cn|date=July 2023}}
* DH keys weaker than 2048 bits.{{cn|date=July 2023}}
* ECDHE keys weaker than 192 bits; also, not all known older named curves still in use for this are vetted "safe".{{cn|date=July 2023}}
* DHE/EDHE is guessable/weak when using/re-using known default prime values on the server
* The [[Cipher block chaining|CBC]] block cipher mode of operation is considered weak for TLS (the CCM/GCM modes are now recommended).{{cn|date=July 2023}}