Cocks proposed a protocol for two parties to jointly generate a shared RSA key. His protocol was designed under the assumption
that both parties follow the protocol. Cocks proposed a modification to the protocol to prevent certain attacks by an active
adversary. The paper presents attacks that show that the Cocks protocols are not secure when one party deviates from the protocol.