Curated internet, served daily

Cracking a 1999 Certificate Authority Key in 32 Hours

A developer factored a 512-bit root CA key from the Netscape era, proving early web cryptography relied on dangerously weak standards.

Factoring a 512-bit RSA key is trivial for a modern desktop, but only if the key is old enough. In 1999, Netscape shipped browsers with root certificates from E-Certify that were exactly this size, leaving the early web PKI with a significant blind spot.

The math is simple: 512 bits is too small. A developer ran CADO-NFS on a Ryzen 9 5950X, taking 32 hours to extract the private keys for E-Certify’s SSL and S/MIME roots. These keys were removed from Netscape in 2002, but the underlying weakness was already known.

The era lacked minimum standards, and export restrictions on cryptography meant that small keys were common in browser installers.

I ran the numbers on this myself. The gap between a 1999 browser and a modern TLS stack is wide, but the private key is just a number.

If I had a Netscape 4.51 VM with a backdated clock, I could issue valid certificates. It is a niche exploit, but it proves that the early web was held together by significantly weaker glue than we assumed.

Skip it if you only care about current TLS implementations. The vulnerability is dead, but the history is useful. Check the GitHub repo to see the extracted keys and the custom Go-based TLS server that makes them work.

← Back to Daily