Hacker News
Two 1990s Certificate Authority Roots Had Their 512-Bit RSA Keys Factored on a Desktop in 32 Hours
In a September 7 writeup, the author factored the 512-bit RSA keys of E-Certify RSA 512 Gold (both the SSL server and client roots) using CADO-NFS on a single Ryzen 9 5950X, taking 32 hours and 29 hours respectively; a colleague factored the VeriSign Test Commercial Software Publisher CA key in about an hour on a GPU cluster. These roots shipped in Netscape browsers in the 1990s and E-Certify's were removed in 2002, three years after RSA-155 fell in 1999. The point is not a live break but the record it leaves: the early Web PKI had no minimum key size requirement, and those roots remain forgeable in any archived trust store still carrying them.
↳ Follow the thread