A researcher successfully factored the 512-bit RSA keys associated with E-Certify, a Canadian certificate authority that operated in the late 1990s. These specific root certificates were distributed with Netscape Navigator version 4.51 in March 1999, providing SSL and S/MIME trust.
The factorization highlights the historical weakness of smaller RSA key lengths. While 1024-bit RSA was deprecated over a decade ago, 512-bit RSA was already considered insecure and had been factored by late 1999, the same year Netscape shipped these roots.
The security of RSA cryptography relies on the computational difficulty of factoring large semiprime numbers. The definition of a "large" number has evolved significantly over time. In the early days of the Web PKI, standards for minimum key sizes were not as established, and export restrictions on cryptography influenced key length choices.
Today, the industry standard for RSA keys is at least 2048 bits, with ongoing discussions about future deprecation due to advancements in computing and the potential threat of quantum computers.
To find suitable targets, the researcher accessed archives of old browser installers from archive.org, extracting root certificates from both Internet Explorer and Netscape. A Claude-generated webpage was used to filter and identify small keys trusted for SSL. This process led to the discovery of the 512-bit E-Certify roots.
Internet Explorer did not appear to have shipped any 512-bit roots for SSL, limiting the scope of this particular factorization to Netscape's historical distribution.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A researcher successfully factored the 512-bit RSA keys of E-Certify, a defunct Canadian certificate authority whose roots were shipped with Netscape 4.51 in 1999. This demonstrates the vulnerability of older, smaller RSA key sizes, which were considered weak even at the time of their use.