A security researcher has successfully factored the RSA keys of a Certificate Authority active in the 1990s, exposing fundamental flaws in early cryptographic implementations. The breakthrough demonstrates that decades-old digital certificates used by this authority can now be fully compromised.

What You Need to Know

Factoring RSA private keys from a long‑dormant Certificate Authority reveals that weak prime generation plagued early cryptography. Modern browsers and operating systems may still trust legacy root certificates issued by that authority, creating potential attack vectors. This incident highlights the importance of retiring outdated cryptographic standards and auditing old key material.

The Factorization Feat

Using commodity hardware and well‑known algorithms, the researcher derived the private RSA keys from public certificates once signed by a 1990s era Certificate Authority. The keys relied on small primes, making them vulnerable to integer factorization despite RSA’s theoretical security. The authority itself had been defunct for years, but its root certificates remain embedded in several trusted store lists.

  • Weak Prime Generation: Early key pairs often reused prime factors across certificates, drastically reducing cracking difficulty.
  • Obsolete Key Sizes: Many 1990s CAs used 512‑bit RSA keys, which are trivially breakable today.
  • No Revocation Infrastructure: Legacy root certificates lack modern revocation mechanisms such as CRL or OCSP stapling.

Historical Context

During the 1990s, the Certificate Authority ecosystem was nascent. Export restrictions limited key sizes, and best practices for random number generation were not yet codified. As a result, many early CAs produced keys with insufficient entropy. Although most have since been replaced, some older roots remain in browser trust stores due to backward‑compatibility concerns.

Why This Matters

This demonstration shifts the theoretical risk of outdated cryptographic material into a concrete threat. If malicious actors could replicate the factorization against still‑trusted root certificates, they could forge TLS certificates for any domain covered by that chain of trust. Enterprises relying on legacy hardware or software that pins those certificates face exposure. The findings pressure industry bodies like Mozilla and Apple to accelerate audits of historical roots and mandate stronger key generation practices.

  • Increased Audit Frequency: Trust stores may now require periodic review of all pre‑2000 roots.
  • Tighter Revocation Policies: Expect faster deprecation of certificates using sub‑2048‑bit RSA keys.
  • Shift Toward Forward Secrecy: The event reinforces migration to ECDHE ciphersuites, which limit impact of private key compromise.

What Comes Next

Browser vendors are evaluating removal of any root certificate issued by a 1990s CA that cannot prove its key generation met modern standards. Meanwhile, cryptographers recommend that organizations search their internal trust stores for residual legacy certificates and prepare contingency plans. The factoring exercise serves as a real‑world warning: even defunct Certificate Authorities can echo into present‑day security if their keys were weak.