I factored the RSA keys of a 1990s Certificate Authority

I've factored the RSA keys of a Certificate Authority from the 90s

I factored the RSA keys of a 1990s Certificate Authority

The author extracts 512-bit RSA root certificates from archived Netscape and Internet Explorer installers, finds two from the defunct Canadian CA E-Certify, and factors them with CADO-NFS on a desktop in about 30 hours each. They reconstruct the private keys, set up a VM running Netscape 4.51, and build a custom TLS server in Go to issue and verify certificates, hosting a live demo at e-certify.fly.dev. The post includes keys, tools, and a bonus factored VeriSign test CA.

This describes zero people on the planet… except for this VM I set up.
  1. hnmullany

    I was the product manager with responsibility for root certificates in the Netscape 4.51 browser. It's crazy to see someone factor it 25 years later.

    Just to reply to some people in the comments. Yes, we knew export grade encryption was weak - that was the point - that the NSA could decrypt it - and the govt. required us to do it anyway.

    FWIW - we had the goal of expanding the list of root authorities in the 4.5x release - and this might have been the first release to monetize the root slots because Netscape was under severe pressure to generate revenue.

    (Also - Verisign hated that we were expanding competition and tried to convince us to implement a program that would re-restrict the list to a set of "responsible" companies aka Verisign and one or two others. We declined.)

  2. 63

    A bit unfortunate that so many of the interesting bits were left to ai. I would've enjoyed some commentary on why the custom TLS implementation was necessary. Oh well.

    Update: found this explanation in a comment at the top of the (surprisingly short) Go file in the linked repo:

    The target client is Netscape Communicator 4.51 (both the 40-bit export build and the 128-bit US build) with its clock set to the year 2000.

    Go's crypto/tls cannot help: it dropped SSLv3 in Go 1.14, never accepted the SSLv2-compatible ClientHello that Netscape 4 sends, and never had RC4-MD5 or the 40-bit export suites. So this file carries its own tiny SSLv3 server-side implementation on top of stdlib primitives (RSA PKCS#1 v1.5, RC4, DES, 3DES, MD5, SHA-1). The server key is 512-bit RSA so that export clients can encrypt the premaster secret to it directly, without a ServerKeyExchange.

  3. goalieca

    Basically 2 days on a consumer GPU to crack a 512 bit cert. The thing is much of the traffic back then did not use ephemeral keys. Most of it wasn't even encrypted at all! But about a decade later, it became normal to encrypt everything. I do wonder which governments around the world are just waiting to crack anonymous political speech by recording and saving for later when decryption can happen.

  4. alexpotato

    I owned the "broker FTP" service at a hedge fund.

    There was a project in 2021 to talk to the banks and brokers that we connected and ask them to upgrade their keys and ciphers to modern versions.

    IIRC, the oldest key/cipher was from the late 2000s so it wouldn't surprise me if someone is using RSA keys from the 90s somewhere.

    You can read more about how hedge funds use FTP here:

    https://x.com/alexpotato/status/1809579426687983657?s=20

    Or listen to patio11 and I talk about these systems in general here:

    https://www.complexsystemspodcast.com/episodes/two-banks-can...

  5. teiferer

    > I don’t have any good reason to do that, but it seems like fun.

    What better reason is there to do something than it being fun?

  6. pvillano

    That SSL report with four different automatic 'F's is an amazing punchline

  7. gadders

    I womder if you could do the old Lotus Notes weak non-US Keys now, and if there are any old .nsf files floating around to be decrypted.

  8. tunahanfaruksav

    Great writeup. The fact that CADO-NFS still takes 32 hours on a 5950X for a 512-bit key that's trivial by today's academic standards really puts into perspective how comically undersized these were even for 1999 — RSA-155 fell that same year. Also love that verifying against real Netscape 4.51 ended up being harder than the factoring itself.

More from this day

2026-09-08