Researcher cracks a 1999 CA's 512-bit keys - but the only victim is his own VM
A hobby project spent 61 hours of desktop compute breaking encryption that Netscape itself gave up on in 2002 - here's why nobody today should lose sleep over it.
The claim
A developer called Matthew McPherrin says he’s factored the 512-bit RSA keys belonging to a long-dead certificate authority - the kind of maths that underpins HTTPS padlocks. That sounds alarming until you learn the certificate authority in question was called E-Certify, it shut down decades ago, and the browser it was trusted by stopped shipping in the early 2000s. This is less “modern web security is broken” and more “vintage lock, cracked for fun”.
What actually happened
RSA security depends on how hard it is to factor a very large number into its two prime components. The bigger the number, the harder the sum. Today’s web certificates use at least 2048-bit RSA keys, which remain far out of reach of anyone’s desktop PC. But rewind to 1999, when Netscape 4.51 shipped trusting two 512-bit root certificates from a Canadian CA called E-Certify - one for securing websites, one for S/MIME email encryption.
Even by the standards of the time, 512-bit RSA was thin. The same year those roots shipped, a 512-bit key (RSA-155) was publicly factored by researchers - proof this key size was already too weak for serious use. Netscape quietly dropped the E-Certify roots from its trusted list in 2002.
McPherrin, who works in the CA industry, went looking for old, weak root certificates by digging through archived copies of Netscape and Internet Explorer installers on the Internet Archive, cataloguing what he found with help from an AI coding assistant. He then set a piece of specialist factoring software called CADO-NFS loose on his home PC - a Ryzen 9 5950X - and after 32 hours cracked the SSL key, and another 29 hours cracked the S/MIME one.
Having the private key means he can, in theory, issue certificates that a suitably ancient browser would trust as genuine. To prove it worked, he had to build a custom mini web server from scratch, because modern software (including Go’s standard TLS library and stock OpenSSL) has long since stripped out support for the obsolete ciphers and handshake styles that Netscape 4.51 used. He’s hosted the resulting demo, along with the recovered keys, publicly for anyone curious enough to try connecting with a 26-year-old browser.
So who is actually at risk
Nobody. To exploit this, you’d need to be running Netscape Communicator 4.51 - a browser abandoned in the early 2000s - with your system clock manually wound back to before October 2003, when the E-Certify roots expired. As McPherrin puts it, that describes essentially zero people on the planet, bar the test virtual machine he built himself. Today’s browsers, certificate authorities and TLS standards have nothing to do with E-Certify or 512-bit keys; the modern web moved to 2048-bit RSA (and increasingly elliptic-curve cryptography) long ago, specifically because short keys like this were shown to be crackable.
What it actually demonstrates
The interesting takeaway isn’t a security hole - it’s a reminder of how quickly “secure” becomes “quaint”. A key size trusted by a major browser in 1999 is now within reach of a single well-specced gaming PC left running for a couple of days. It’s also a useful data point for the bigger conversation happening in cryptography right now: today’s 2048-bit keys are safe from home computers, but nobody assumes they’ll stay unbreakable forever, especially once quantum computing matures.
The takeaway
This is a neat piece of retro-computing archaeology, not a live threat. If you’re not running a museum-piece browser with your clock set to 1999, this affects you not at all.