A researcher factored three 512-bit RSA keys from a defunct 1999 Canadian certificate authority in under 32 hours each on a single Ryzen 9 5950X desktop, using the open-source CADO-NFS tool. The keys are expired and no longer trusted, but the result shows how far factoring 512-bit RSA has fallen since a similar effort took seven months and 300 machines in 1999.
Read the full story: Researcher Factors 512-bit RSA Keys From a 1999 Root CA →
Transcript
A security researcher just factored the private keys of a certificate authority that hasn't existed in over twenty years. Matthew McPherrin pulled root certificates out of Netscape Navigator 4.51, from 1999, and found three 512-bit RSA keys still sitting inside. Using an open-source tool called CADO-NFS, he cracked each one in under 32 hours, on a single Ryzen 9 desktop, nothing more.
That number matters because in 1999, breaking a key that size took a coordinated team seven months and 300 machines. These particular certificates expired decades ago, so nothing modern is actually at risk. But the technique is the real headline. Old root stores are full of relics like this, and factoring them just got a lot easier.