Fetching from the wire…
Public story · 2026-09-08 · high
512-bit RSA keys from Netscape-era certificate authorities fell in hours, one on a single gaming PC.
Why now: The factoring writeup posted September 7, 2026.
Two root certificate authorities that Netscape shipped in the 1990s had their 512-bit RSA keys factored on a single desktop computer, per the CADO-NFS factoring writeup posted September 7. The target was E-Certify RSA 512 Gold's SSL server and client roots, cracked on a single Ryzen 9 5950X. The server key fell in 32 hours, the client key in 29. A colleague went further, factoring the VeriSign Test Commercial Software Publisher CA key in about an hour on a GPU cluster.
None of this breaks anything live. Browsers dropped both roots in 2002, and the certificate authorities behind them are gone. What the result confirms is how weak the early Web PKI's rules were. There was no enforced minimum key size, and any archived trust store still carrying these roots is forgeable on a gaming PC over a weekend.
That matters wherever these roots are still trusted outside a current browser, in an old certificate bundle nobody has updated. A certificate forged against E-Certify RSA 512 Gold or the VeriSign test root would still validate anywhere that bundle is in use.
The writeup doesn't say how many systems still carry these specific roots, and there's no registry that would answer that question either. The E-Certify keys fell to one chip working alone; the VeriSign key needed a cluster. 512-bit RSA no longer needs a lab, just a day and a half of patience on a single computer.
Each link below shares sources, entities, or timing with this story.
Ollama cut v0.34.0-rc1 on September 5 at 23:49 UTC, and the headline item changes the shape of the local-versus-hosted decision rather than the performance of either side: Ollama-hosted open models can be selected directly inside ChatGPT Desktop, with setup driven from the Oll...
Pair this with the espionage story and the picture gets uncomfortable fast. A new arXiv paper (2603.21642) presents the first systematic evaluation of prompt injection through tool-poisoning across seven MCP clients: Claude Desktop, Claude Code, Cursor, Cline, Continue, Gemini...
Two AMD Radeon R9700 32GB at PCIe 5.0 x8 each, a Ryzen 7500F, 64GB DDR5 CL40 6400 MT/s on an ASUS ProArt X870E, running Ubuntu with vLLM against Qwen 3.8 27B in FP8 and MXFP4 plus Flash Next (r/LocalLLaMA). Two practical findings: an old SATA Samsung EVO 860 is not a bottlenec...
arXiv 2609.03893 argues that microarchitectural side-channel work compares against numbers lifted from prior papers, using proxies like covert-channel bandwidth or key recovery against naive AES and RSA. These attacks are acutely sensitive to experimental conditions, so small...
SBW determines green-list membership through independent per-token Bernoulli trials rather than KGW's vocabulary permutation or SynthID's tournament, requiring one comparison per token against a counter-based RNG, which enables single-kernel execution with zero intermediate al...
Co-led by Atreides Management and Valor Equity Partners with Mubadala Capital participating, against the $10B valuation from its $1.38B round last October, and following a $13B five-year GPU cloud contract with Jane Street. Meta, Microsoft and OpenAI are all customers. TechCrunch
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.