While at first it may seem an unlikely attack, it's probably more real than you'd think, given the number of times any single server does TLS negotiation using a given private key. The attack becomes even more likely when you realize that multiple servers will be using the private key.
In practice, this gives middle boxes more power, and raises their profile in the threat model significantly. This also opens up the possibility of simply collecting failed transient failed tls negotation data from a large number of (legitimate) clients to reconstruct a private key.
now put your tinfoil hat on and suppose you worked for a paramilitary organization that had infiltrated the top 2 semiconductor manufacturers. You persuade the silicon designers, when implementing hardware accelerated crypto (or "management engines") to not do their jobs quite perfectly, no just leave room for a tiny bit of....error. Could never happen, right?
Edit: Don't ask me questions, i don't know shit, i just rephrased stuff from the linked paper.
> Our combined dataset of around 5.2 billion SSH records contained more than 590,000 invalid RSA signatures.
Seems like over long periods, it can occur a spoopy amount of time.
>An RSA public key consists of a public exponent ๐ and a modulus ๐ = ๐๐ that is the product of two primes. The private key consists of the private exponent ๐ = ๐ โ1 mod ๐ (๐) and ๐ . A textbook RSA signature on a message ๐ is the value ๐ = ๐๐ mod ๐ . To verify the signature, a user checks if ๐ ๐ mod ๐ = ๐
> these attacks exploit the fact that if an error is made while computing modulo one prime, say ๐, then the resulting invalid signature ห๐ is equivalent to the correct signature modulo one prime factor ๐, but not ๐. 2.2.1 GCD attack on fully known messages. Boneh, DeMillo, and Lipton noted [11] that if an attacker had a correct signature ๐ and an incorrect signature ห๐ of this form then the attacker could compute gcd(๐, ห๐ โ ๐ ) = ๐