From Adam Langley, who works at Google on their SSL stack, on his post "How to botch TLS forward secrecy":
In the case of multiplicative Diffie-Hellman (i.e. DHE), servers are free to choose their own, arbitrary DH groups. <snip> ... it's still the case that some servers use 512-bit DH groups, meaning that the connection can be broken open with relatively little effort.
Full article of his at https://www.imperialviolet.org/