A desktop just factored the 512-bit RSA keys of a 1999 Netscape certificate authority

“The certificate authority that once told Netscape who to trust just got its private keys factored on a gaming PC.”

The Story

Using CADO-NFS on a Ryzen desktop, a researcher factored the two 512-bit RSA roots that Netscape 4.51 shipped in 1999 from the long-dead Canadian CA E-Certify (SSL and S/MIME). The keys were already too weak in their era and were later removed, but they still exist as historical artifacts. Anyone with a time-warped Netscape could now mint certs.

Why It Matters

Builders + decaying trust infrastructure. The old web’s identity layer is now a weekend hobby. Concrete keys, not abstract crypto.

Evidence

Matthew McPherrin’s post (HN front-page) with the actual private keys and method.

Sources

Daily scan: 2026-09-08