2026-09-08 / Signal #5
A desktop just factored the 512-bit RSA keys of a 1999 Netscape certificate authority
“The certificate authority that once told Netscape who to trust just got its private keys factored on a gaming PC.”
The Story
Using CADO-NFS on a Ryzen desktop, a researcher factored the two 512-bit RSA roots that Netscape 4.51 shipped in 1999 from the long-dead Canadian CA E-Certify (SSL and S/MIME). The keys were already too weak in their era and were later removed, but they still exist as historical artifacts. Anyone with a time-warped Netscape could now mint certs.
Why It Matters
Builders + decaying trust infrastructure. The old web’s identity layer is now a weekend hobby. Concrete keys, not abstract crypto.
Evidence
Matthew McPherrin’s post (HN front-page) with the actual private keys and method.
Sources
Daily scan: 2026-09-08